Debian

Debian Linux

9952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.17%
  • Veröffentlicht 27.12.2019 08:15:09
  • Zuletzt bearbeitet 21.11.2024 04:37:56

In in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in WordPress 3.7 to 5.3.0, authenticated users who do not have the rights to publish a post are able to mark posts as sticky or unsticky via the REST API. For example, the contri...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 26.12.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 01:39:32

In NetworkManager 0.9.2.0, when a new wireless network was created with WPA/WPA2 security in AdHoc mode, it created an open/insecure network.

  • EPSS 3.61%
  • Veröffentlicht 26.12.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:31:10

WordPress users with lower privileges (like contributors) can inject JavaScript code in the block editor using a specific payload, which is executed within the dashboard. This can lead to XSS if an admin opens the post in the editor. Execution of thi...

  • EPSS 3.49%
  • Veröffentlicht 26.12.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:31:10

In WordPress before 5.3.1, authenticated users with lower privileges (like contributors) can inject JavaScript code in the block editor, which is executed within the dashboard. It can lead to an admin opening the affected post in the editor leading t...

  • EPSS 0.88%
  • Veröffentlicht 26.12.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:31:11

In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Spec...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 25.12.2019 04:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:45

In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 25.12.2019 04:15:12
  • Zuletzt bearbeitet 21.11.2024 04:35:45

In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655.

  • EPSS 7.01%
  • Veröffentlicht 24.12.2019 17:15:10
  • Zuletzt bearbeitet 21.11.2024 04:35:40

zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.

  • EPSS 6.2%
  • Veröffentlicht 24.12.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:40

flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).

  • EPSS 0.15%
  • Veröffentlicht 24.12.2019 16:15:11
  • Zuletzt bearbeitet 03.12.2025 19:15:50

xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.