Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 18.12.2020 08:15:15
  • Zuletzt bearbeitet 21.11.2024 05:27:22

An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing s...

Exploit
  • EPSS 3.92%
  • Veröffentlicht 17.12.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:27:24

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.

Exploit
  • EPSS 5.71%
  • Veröffentlicht 17.12.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:27:24

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.

  • EPSS 0.24%
  • Veröffentlicht 16.12.2020 14:15:12
  • Zuletzt bearbeitet 21.11.2024 05:23:54

An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or callo...

  • EPSS 0.36%
  • Veröffentlicht 16.12.2020 14:15:12
  • Zuletzt bearbeitet 21.11.2024 05:23:54

An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in ...

Exploit
  • EPSS 93.68%
  • Veröffentlicht 16.12.2020 01:15:12
  • Zuletzt bearbeitet 23.05.2025 16:53:23

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data fro...

Exploit
  • EPSS 88.87%
  • Veröffentlicht 16.12.2020 01:15:12
  • Zuletzt bearbeitet 23.05.2025 16:54:02

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remote attacker to delete arbitrar...

  • EPSS 0.06%
  • Veröffentlicht 15.12.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 05:24:04

An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for every created...

  • EPSS 0.07%
  • Veröffentlicht 15.12.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 05:24:04

An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid wil...

  • EPSS 0.06%
  • Veröffentlicht 15.12.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 05:24:04

An issue was discovered in Xen through 4.14.x. A guest may access xenstore paths via absolute paths containing a full pathname, or via a relative path, which implicitly includes /local/domain/$DOMID for their own domain id. Management tools must acce...