Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 08.12.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:30:56

In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

Exploit
  • EPSS 2.04%
  • Veröffentlicht 07.12.2021 22:15:06
  • Zuletzt bearbeitet 03.07.2025 20:59:18

ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP ...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 06.12.2021 18:15:08
  • Zuletzt bearbeitet 21.11.2024 06:29:46

runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc, netlink is used internally as a serialization system for specifying the relevant container configuration to the `C` portion of the code (resp...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 06.12.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:36:50

vim is vulnerable to Use After Free

  • EPSS 0.34%
  • Veröffentlicht 02.12.2021 03:15:06
  • Zuletzt bearbeitet 21.11.2024 06:30:37

In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 01.12.2021 11:15:07
  • Zuletzt bearbeitet 21.11.2024 06:23:18

vim is vulnerable to Heap-based Buffer Overflow

Exploit
  • EPSS 0.21%
  • Veröffentlicht 01.12.2021 10:15:07
  • Zuletzt bearbeitet 03.11.2025 21:15:47

vim is vulnerable to Heap-based Buffer Overflow

Exploit
  • EPSS 0.04%
  • Veröffentlicht 29.11.2021 08:15:07
  • Zuletzt bearbeitet 21.11.2024 04:50:39

An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buf...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 29.11.2021 08:15:07
  • Zuletzt bearbeitet 21.11.2024 04:50:39

A heap-based buffer overflow was discovered in bluetoothd in BlueZ through 5.48. There isn't any check on whether there is enough space in the destination buffer. The function simply appends all data passed to it. The values of all attributes that ar...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 29.11.2021 07:15:06
  • Zuletzt bearbeitet 21.11.2024 05:48:52

In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simplexml_load_file(), URL-decode the filename passed to them. If that filename contains URL-encoded NUL character, this may cause the ...