Debian

Debian Linux

9198 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.56%
  • Veröffentlicht 26.11.2019 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:01

An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypasse...

  • EPSS 33.64%
  • Veröffentlicht 26.11.2019 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:02

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the ...

Exploit
  • EPSS 25.88%
  • Veröffentlicht 26.11.2019 05:15:14
  • Zuletzt bearbeitet 21.11.2024 01:32:17

Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.

  • EPSS 1.48%
  • Veröffentlicht 26.11.2019 05:15:13
  • Zuletzt bearbeitet 21.11.2024 01:31:53

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common...

  • EPSS 0.92%
  • Veröffentlicht 26.11.2019 05:15:11
  • Zuletzt bearbeitet 21.11.2024 01:31:48

A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request.

  • EPSS 4.16%
  • Veröffentlicht 26.11.2019 04:15:11
  • Zuletzt bearbeitet 21.11.2024 01:30:53

Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a speciall...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 26.11.2019 04:15:11
  • Zuletzt bearbeitet 21.11.2024 01:30:53

Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.

  • EPSS 3.12%
  • Veröffentlicht 26.11.2019 04:15:10
  • Zuletzt bearbeitet 21.11.2024 01:30:53

Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user...

  • EPSS 0.28%
  • Veröffentlicht 26.11.2019 03:15:10
  • Zuletzt bearbeitet 21.11.2024 01:30:51

Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.

Exploit
  • EPSS 1.51%
  • Veröffentlicht 26.11.2019 00:15:11
  • Zuletzt bearbeitet 21.11.2024 01:30:22

It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.