Debian

Debian Linux

9928 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 25.22%
  • Veröffentlicht 21.06.2020 17:15:09
  • Zuletzt bearbeitet 21.11.2024 05:04:30

Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates i...

  • EPSS 0.38%
  • Veröffentlicht 19.06.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:04:27

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they w...

Exploit
  • EPSS 90.13%
  • Veröffentlicht 19.06.2020 18:15:11
  • Zuletzt bearbeitet 09.05.2025 20:15:36

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 19.06.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 05:38:25

A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

Exploit
  • EPSS 1.55%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:38:24

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

Exploit
  • EPSS 7.39%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:38:25

A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.

Exploit
  • EPSS 1.05%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:38:27

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.

  • EPSS 0.07%
  • Veröffentlicht 18.06.2020 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:24:05

In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data can be extracted by knowing t...

  • EPSS 0.14%
  • Veröffentlicht 18.06.2020 03:15:14
  • Zuletzt bearbeitet 21.11.2024 05:30:51

A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition th...

  • EPSS 6.93%
  • Veröffentlicht 17.06.2020 22:15:13
  • Zuletzt bearbeitet 21.11.2024 05:39:08

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone ...