Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.08%
  • Veröffentlicht 20.07.2021 19:15:09
  • Zuletzt bearbeitet 09.06.2025 16:15:32

basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.

Exploit
  • EPSS 0.81%
  • Veröffentlicht 20.07.2021 15:15:11
  • Zuletzt bearbeitet 21.11.2024 06:21:09

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.

Exploit
  • EPSS 0.76%
  • Veröffentlicht 20.07.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:49:45

Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file

  • EPSS 0.05%
  • Veröffentlicht 20.07.2021 07:15:07
  • Zuletzt bearbeitet 21.11.2024 04:39:50

objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).

Exploit
  • EPSS 0.52%
  • Veröffentlicht 19.07.2021 17:15:11
  • Zuletzt bearbeitet 03.12.2025 16:15:53

An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.

  • EPSS 0.34%
  • Veröffentlicht 19.07.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:29:28

An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.

  • EPSS 0.66%
  • Veröffentlicht 19.07.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:29:28

An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.

  • EPSS 0.13%
  • Veröffentlicht 19.07.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:29:28

An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 19.07.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:29:28

An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

  • EPSS 1.04%
  • Veröffentlicht 19.07.2021 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:29:28

An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).