Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.95%
  • Veröffentlicht 04.12.2022 03:15:09
  • Zuletzt bearbeitet 24.04.2025 16:15:23

AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.

  • EPSS 0.21%
  • Veröffentlicht 03.12.2022 15:15:09
  • Zuletzt bearbeitet 24.04.2025 16:15:18

Prior to Apache Commons Net 3.9.0, Net's FTP client trusts the host from PASV response by default. A malicious server can redirect the Commons Net code to use a different host, but the user has to connect to the malicious server in the first place. T...

  • EPSS 0.24%
  • Veröffentlicht 30.11.2022 06:15:11
  • Zuletzt bearbeitet 24.04.2025 19:15:44

g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writable, allowing any process on the system to read traffic from keyboards, including sensitive data.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 28.11.2022 21:15:10
  • Zuletzt bearbeitet 04.11.2025 16:15:52

Sinatra is a domain-specific language for creating web applications in Ruby. An issue was discovered in Sinatra 2.0 before 2.2.3 and 3.0 before 3.0.4. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Dispos...

  • EPSS 0.04%
  • Veröffentlicht 28.11.2022 06:15:10
  • Zuletzt bearbeitet 28.04.2025 19:15:46

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may u...

  • EPSS 0.41%
  • Veröffentlicht 27.11.2022 04:15:10
  • Zuletzt bearbeitet 29.04.2025 14:15:30

An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.

Exploit
  • EPSS 1.14%
  • Veröffentlicht 26.11.2022 22:15:10
  • Zuletzt bearbeitet 29.04.2025 14:15:20

qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attack...

  • EPSS 2.76%
  • Veröffentlicht 23.11.2022 21:15:11
  • Zuletzt bearbeitet 25.04.2025 20:15:35

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 23.11.2022 20:15:10
  • Zuletzt bearbeitet 03.11.2025 22:16:00

pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is ...

  • EPSS 0.4%
  • Veröffentlicht 22.11.2022 02:15:11
  • Zuletzt bearbeitet 03.11.2025 22:15:59

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476...