Debian

Debian Linux

9951 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 22.06.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:56:46

In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2.

  • EPSS 0.18%
  • Veröffentlicht 22.06.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 04:56:47

In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.

  • EPSS 0.24%
  • Veröffentlicht 22.06.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:56:46

In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.

  • EPSS 5.78%
  • Veröffentlicht 21.06.2020 17:15:09
  • Zuletzt bearbeitet 21.11.2024 05:04:30

Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates i...

  • EPSS 0.38%
  • Veröffentlicht 19.06.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:04:27

Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they w...

Exploit
  • EPSS 90.13%
  • Veröffentlicht 19.06.2020 18:15:11
  • Zuletzt bearbeitet 09.05.2025 20:15:36

A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 19.06.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 05:38:25

A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains.

Exploit
  • EPSS 1.55%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:38:24

A client side enforcement of server side security vulnerability exists in rails < 5.2.4.2 and rails < 6.0.3.1 ActiveStorage's S3 adapter that allows the Content-Length of a direct file upload to be modified by an end user bypassing upload limits.

Exploit
  • EPSS 7.39%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:38:25

A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.

Exploit
  • EPSS 1.16%
  • Veröffentlicht 19.06.2020 17:15:18
  • Zuletzt bearbeitet 21.11.2024 05:38:27

A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.