Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.72%
  • Veröffentlicht 16.09.2021 15:15:07
  • Zuletzt bearbeitet 01.05.2025 15:40:05

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).

  • EPSS 37.67%
  • Veröffentlicht 16.09.2021 15:15:07
  • Zuletzt bearbeitet 01.05.2025 15:39:40

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

Warnung
  • EPSS 94.43%
  • Veröffentlicht 16.09.2021 15:15:07
  • Zuletzt bearbeitet 27.10.2025 17:37:06

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

  • EPSS 0.1%
  • Veröffentlicht 16.09.2021 15:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:24

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an in...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 15.09.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:22:27

vim is vulnerable to Use After Free

Exploit
  • EPSS 0.38%
  • Veröffentlicht 15.09.2021 08:15:06
  • Zuletzt bearbeitet 21.11.2024 06:22:24

vim is vulnerable to Heap-based Buffer Overflow

Exploit
  • EPSS 3.59%
  • Veröffentlicht 14.09.2021 01:15:07
  • Zuletzt bearbeitet 21.11.2024 06:25:22

squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents under the same filename in a fi...

Exploit
  • EPSS 0.48%
  • Veröffentlicht 13.09.2021 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:21

tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.

  • EPSS 1.77%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:52

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like no...

  • EPSS 0.5%
  • Veröffentlicht 09.09.2021 22:15:09
  • Zuletzt bearbeitet 21.11.2024 06:18:53

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. ### Impact The issue allows an authenticated but low-privileged user (like contributor/author) to execute XSS in the editor. Thi...