Debian

Debian Linux

9144 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.3%
  • Veröffentlicht 15.02.2021 13:15:12
  • Zuletzt bearbeitet 21.11.2024 05:51:31

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector c...

Exploit
  • EPSS 6.74%
  • Veröffentlicht 15.02.2021 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:36:37

In PHP versions 7.3.x below 7.3.26, 7.4.x below 7.4.14 and 8.0.0, when validating URL with functions like filter_var($url, FILTER_VALIDATE_URL), PHP will accept an URL with invalid password as valid URL. This may lead to functions that rely on URL be...

  • EPSS 0.25%
  • Veröffentlicht 15.02.2021 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:48:51

In PHP versions 7.3.x below 7.3.27, 7.4.x below 7.4.15 and 8.0.x below 8.0.2, when using SOAP extension to connect to a SOAP server, a malicious SOAP server could return malformed XML data as a response that would cause PHP to access a null pointer a...

Exploit
  • EPSS 3.5%
  • Veröffentlicht 14.02.2021 04:15:12
  • Zuletzt bearbeitet 21.11.2024 05:57:04

An XSS issue was discovered in Horde Groupware Webmail Edition through 5.2.22 (where the Horde_Text_Filter library before 2.3.7 is used). The attacker can send a plain text e-mail message, with JavaScript encoded as a link or email that is mishandled...

Exploit
  • EPSS 22.8%
  • Veröffentlicht 14.02.2021 03:15:12
  • Zuletzt bearbeitet 21.11.2024 05:57:36

In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemon exit) via a short timestamp. This is related to s...

Warnung Exploit
  • EPSS 93.75%
  • Veröffentlicht 11.02.2021 21:15:13
  • Zuletzt bearbeitet 24.10.2025 14:48:35

Adminer is an open-source database management in a single PHP file. In adminer from version 4.0.0 and before 4.7.9 there is a server-side request forgery vulnerability. Users of Adminer versions bundling all drivers (e.g. `adminer.php`) are affected....

  • EPSS 7.38%
  • Veröffentlicht 11.02.2021 18:15:15
  • Zuletzt bearbeitet 23.04.2025 20:15:20

A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow in the kernel to be too wide, potentially causing a ...

  • EPSS 14.37%
  • Veröffentlicht 10.02.2021 17:15:19
  • Zuletzt bearbeitet 21.11.2024 05:42:31

In p2p_copy_client_info of p2p.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if the target device is performing a Wi-Fi Direct search, with no additional execution privileges needed...

  • EPSS 0.87%
  • Veröffentlicht 10.02.2021 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:57:23

xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.

  • EPSS 1.33%
  • Veröffentlicht 10.02.2021 07:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:08

The daemon in GENIVI diagnostic log and trace (DLT), is vulnerable to a heap-based buffer overflow that could allow an attacker to remotely execute arbitrary code on the DLT-Daemon (versions prior to 2.18.6).