Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.58%
  • Veröffentlicht 13.09.2021 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:21

tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.

  • EPSS 1.77%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:52

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like no...

  • EPSS 0.51%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:53

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. Thi...

  • EPSS 1.5%
  • Veröffentlicht 09.09.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:08:58

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the 'in _TIFFmemcpy' funtion in the component 'tif_unix.c'.

  • EPSS 0.97%
  • Veröffentlicht 09.09.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 05:08:58

Buffer Overflow in LibTiff v4.0.10 allows attackers to cause a denial of service via the "TIFFVGetField" funtion in the component 'libtiff/tif_dir.c'.

  • EPSS 0.45%
  • Veröffentlicht 09.09.2021 14:15:09
  • Zuletzt bearbeitet 21.11.2024 06:22:21

Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network (for example AS 13335 - Clou...

Exploit
  • EPSS 92.85%
  • Veröffentlicht 08.09.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 06:23:54

An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request smuggling attack, allowing an attacker to bypass all configured http-request HAProxy ACLs and possibly other ACLs.

Exploit
  • EPSS 2.76%
  • Veröffentlicht 08.09.2021 16:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:12

A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerabil...

  • EPSS 2.74%
  • Veröffentlicht 08.09.2021 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:49:24

An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.

  • EPSS 0.06%
  • Veröffentlicht 08.09.2021 14:15:08
  • Zuletzt bearbeitet 21.11.2024 06:00:10

Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, ar...