Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.65%
  • Veröffentlicht 30.03.2021 18:15:18
  • Zuletzt bearbeitet 21.11.2024 06:21:37

There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with application availability.

  • EPSS 1.01%
  • Veröffentlicht 30.03.2021 18:15:18
  • Zuletzt bearbeitet 21.11.2024 06:21:38

A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially affecting application availability.

  • EPSS 1.01%
  • Veröffentlicht 30.03.2021 18:15:17
  • Zuletzt bearbeitet 21.11.2024 06:21:37

There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with application availability.

  • EPSS 2.55%
  • Veröffentlicht 30.03.2021 15:15:14
  • Zuletzt bearbeitet 21.11.2024 05:48:17

Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1.61.Final there is a vulnerabi...

  • EPSS 4.29%
  • Veröffentlicht 30.03.2021 07:15:12
  • Zuletzt bearbeitet 21.11.2024 06:01:00

ircII before 20210314 allows remote attackers to cause a denial of service (segmentation fault and client crash, disconnecting the victim from an IRC server) via a crafted CTCP UTC message.

Exploit
  • EPSS 1.08%
  • Veröffentlicht 29.03.2021 14:15:18
  • Zuletzt bearbeitet 03.11.2025 22:15:47

The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

  • EPSS 0.1%
  • Veröffentlicht 26.03.2021 22:15:13
  • Zuletzt bearbeitet 21.11.2024 06:00:54

An issue was discovered in the Linux kernel through 5.11.10. drivers/net/ethernet/freescale/gianfar.c in the Freescale Gianfar Ethernet driver allows attackers to cause a system crash because a negative fragment size is calculated in situations invol...

  • EPSS 0.04%
  • Veröffentlicht 26.03.2021 22:15:13
  • Zuletzt bearbeitet 21.11.2024 06:00:54

An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows attackers to cause a denial of service (GPF) because the stub-up sequence has race conditions during an update of the local and share...

  • EPSS 8.36%
  • Veröffentlicht 25.03.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 06:21:33

An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but incl...

  • EPSS 1.5%
  • Veröffentlicht 25.03.2021 10:15:11
  • Zuletzt bearbeitet 21.11.2024 05:11:42

In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version ...