Debian

Debian Linux

9952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.43%
  • Veröffentlicht 31.12.2019 00:15:12
  • Zuletzt bearbeitet 21.11.2024 04:38:07

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.

Exploit
  • EPSS 0.43%
  • Veröffentlicht 31.12.2019 00:15:12
  • Zuletzt bearbeitet 21.11.2024 04:38:07

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 31.12.2019 00:15:12
  • Zuletzt bearbeitet 21.11.2024 04:38:08

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 31.12.2019 00:15:12
  • Zuletzt bearbeitet 21.11.2024 04:38:08

An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in isomedia/box_code_apple.c.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 30.12.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 01:50:52

A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use ...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 30.12.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 01:44:43

The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

  • EPSS 0.15%
  • Veröffentlicht 30.12.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 01:44:43

Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.

  • EPSS 0.07%
  • Veröffentlicht 30.12.2019 05:15:11
  • Zuletzt bearbeitet 21.11.2024 04:38:03

In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.

  • EPSS 1.37%
  • Veröffentlicht 27.12.2019 08:15:09
  • Zuletzt bearbeitet 21.11.2024 04:37:56

wp_kses_bad_protocol in wp-includes/kses.php in WordPress before 5.3.1 mishandles the HTML5 colon named entity, allowing attackers to bypass input sanitization, as demonstrated by the javascript: substring.

  • EPSS 5.05%
  • Veröffentlicht 27.12.2019 08:15:09
  • Zuletzt bearbeitet 21.11.2024 04:37:56

In wp-includes/formatting.php in WordPress 3.7 to 5.3.0, the function wp_targeted_link_rel() can be used in a particular way to result in a stored cross-site scripting (XSS) vulnerability. This has been patched in WordPress 5.3.1, along with all the ...