Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 08.10.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:16:08

Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • EPSS 0.27%
  • Veröffentlicht 08.10.2021 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:16:08

Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • EPSS 0.06%
  • Veröffentlicht 08.10.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:33

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse ...

  • EPSS 0.32%
  • Veröffentlicht 07.10.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 05:50:56

Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption, to change process behavior.

  • EPSS 0.25%
  • Veröffentlicht 06.10.2021 18:15:10
  • Zuletzt bearbeitet 21.11.2024 06:25:31

Scrapy is a high-level web crawling and scraping framework for Python. If you use `HttpAuthMiddleware` (i.e. the `http_user` and `http_pass` spider attributes) for HTTP authentication, all requests will expose your credentials to the request target. ...

  • EPSS 0.07%
  • Veröffentlicht 06.10.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:00:10

PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform tasks such as legacy USB emulati...

Exploit
  • EPSS 0.93%
  • Veröffentlicht 05.10.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:03

The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access.

  • EPSS 0.51%
  • Veröffentlicht 04.10.2021 21:15:12
  • Zuletzt bearbeitet 21.11.2024 06:07:41

Hiredis is a minimalistic C client library for the Redis database. In affected versions Hiredis is vulnurable to integer overflow if provided maliciously crafted or corrupted `RESP` `mult-bulk` protocol data. When parsing `multi-bulk` (array-like) re...

  • EPSS 0.94%
  • Veröffentlicht 04.10.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:07:41

Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a result of a...

  • EPSS 0.4%
  • Veröffentlicht 04.10.2021 18:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:27

Redis is an open source, in-memory database that persists on disk. An integer overflow bug in the underlying string library can be used to corrupt the heap and potentially result with denial of service or remote code execution. The vulnerability invo...