Debian

Debian Linux

9952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 24.12.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:43

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 24.12.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:43

In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.

Exploit
  • EPSS 1.2%
  • Veröffentlicht 24.12.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:43

In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

Exploit
  • EPSS 1.44%
  • Veröffentlicht 24.12.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:43

In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.

Exploit
  • EPSS 1.31%
  • Veröffentlicht 24.12.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:35:44

In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.

  • EPSS 0.11%
  • Veröffentlicht 24.12.2019 00:15:10
  • Zuletzt bearbeitet 21.11.2024 04:35:43

In the Linux kernel through 5.4.6, there are information leaks of uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c driver, aka CID-da2311a6385c.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 23.12.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:42:06

Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other Kerberos user principals.

Exploit
  • EPSS 0.76%
  • Veröffentlicht 23.12.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:44:22

An exploitable denial-of-service vulnerability exists in the Linux kernel prior to mainline 5.3. An attacker could exploit this vulnerability by triggering AP to send IAPP location updates for stations before the required authentication process has c...

  • EPSS 0.36%
  • Veröffentlicht 23.12.2019 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:22:48

When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perf...

  • EPSS 3.26%
  • Veröffentlicht 23.12.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:32:32

When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be p...