Debian

Debian Linux

9202 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.47%
  • Published 13.11.2019 20:15:10
  • Last modified 21.11.2024 01:21:27

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

  • EPSS 0.28%
  • Published 13.11.2019 19:15:10
  • Last modified 21.11.2024 01:21:09

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.

  • EPSS 0.23%
  • Published 13.11.2019 18:15:10
  • Last modified 21.11.2024 01:21:09

offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.

Exploit
  • EPSS 0.23%
  • Published 13.11.2019 17:15:13
  • Last modified 21.11.2024 01:42:46

letodms 3.3.6 has CSRF via change password

Exploit
  • EPSS 0.45%
  • Published 13.11.2019 16:15:10
  • Last modified 21.11.2024 01:42:46

letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar

  • EPSS 0.81%
  • Published 13.11.2019 14:15:10
  • Last modified 21.11.2024 04:33:12

A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user...

  • EPSS 0.07%
  • Published 12.11.2019 22:15:10
  • Last modified 21.11.2024 01:18:44

babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.

  • EPSS 0.53%
  • Published 12.11.2019 22:15:10
  • Last modified 21.11.2024 01:19:44

An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.

Exploit
  • EPSS 0.15%
  • Published 12.11.2019 21:15:10
  • Last modified 21.11.2024 01:18:27

The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

  • EPSS 0.53%
  • Published 12.11.2019 20:15:09
  • Last modified 21.11.2024 01:18:44

libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disc...