Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.08%
  • Veröffentlicht 07.04.2021 00:15:13
  • Zuletzt bearbeitet 21.11.2024 05:29:14

An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions), aka CID-7be7...

  • EPSS 0.13%
  • Veröffentlicht 06.04.2021 19:15:14
  • Zuletzt bearbeitet 21.11.2024 06:00:08

The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or stale values. This initialization went too far and may under certain conditions also overwrite pointers which are in need of clean...

  • EPSS 1.51%
  • Veröffentlicht 06.04.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 06:00:02

In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vulnerability.

  • EPSS 0.6%
  • Veröffentlicht 06.04.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 06:03:22

phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.

  • EPSS 0.44%
  • Veröffentlicht 06.04.2021 08:15:12
  • Zuletzt bearbeitet 21.11.2024 04:39:46

Redmine before 3.4.13 and 4.x before 4.0.6 mishandles markup data during Textile formatting.

  • EPSS 0.34%
  • Veröffentlicht 06.04.2021 08:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:13

Redmine before 4.0.7 and 4.1.x before 4.1.1 has XSS via the back_url field.

  • EPSS 0.34%
  • Veröffentlicht 06.04.2021 08:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:13

Redmine before 4.0.7 and 4.1.x before 4.1.1 has stored XSS via textile inline links.

  • EPSS 0.45%
  • Veröffentlicht 06.04.2021 08:15:12
  • Zuletzt bearbeitet 21.11.2024 05:29:14

Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.

  • EPSS 0.5%
  • Veröffentlicht 06.04.2021 08:15:12
  • Zuletzt bearbeitet 21.11.2024 06:03:25

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values.

  • EPSS 0.21%
  • Veröffentlicht 06.04.2021 08:15:12
  • Zuletzt bearbeitet 21.11.2024 06:03:26

Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API.