Debian

Debian Linux

9952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.64%
  • Veröffentlicht 15.01.2020 17:15:19
  • Zuletzt bearbeitet 21.11.2024 05:25:40

Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u241, 8u231, 11.0.5 and 13.0.1; Java SE Embedded: 8u231. Difficult to exploit vulnerability allows un...

  • EPSS 0.18%
  • Veröffentlicht 15.01.2020 17:15:13
  • Zuletzt bearbeitet 21.11.2024 02:32:36

The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via crafted query packets.

  • EPSS 0.55%
  • Veröffentlicht 14.01.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 02:18:07

BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via a crafted email address.

  • EPSS 0.44%
  • Veröffentlicht 13.01.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:16

SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.

  • EPSS 0.76%
  • Veröffentlicht 13.01.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:02

PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be...

Exploit
  • EPSS 1.43%
  • Veröffentlicht 13.01.2020 06:15:10
  • Zuletzt bearbeitet 21.11.2024 05:36:17

OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.

Exploit
  • EPSS 2.9%
  • Veröffentlicht 10.01.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:35:36

Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 6.19%
  • Veröffentlicht 10.01.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 04:25:41

Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 0.77%
  • Veröffentlicht 10.01.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:20

Due to improper handling of uploaded images it is possible in very unlikely and rare conditions to force the agents browser to execute malicious javascript from a special crafted SVG file rendered as inline jpg file. This issue affects: ((OTRS)) Comm...

  • EPSS 0.59%
  • Veröffentlicht 10.01.2020 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:20

Agent A is able to save a draft (i.e. for customer reply). Then Agent B can open the draft, change the text completely and send it in the name of Agent A. For the customer it will not be visible that the message was sent by another agent. This issue ...