Debian

Debian Linux

9952 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.11%
  • Veröffentlicht 22.12.2019 20:15:10
  • Zuletzt bearbeitet 21.11.2024 04:35:40

kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us is used (e.g., with Kubernetes), allows attackers to cause a denial of service against non-cpu-bound applications by generating a workload that triggers unwanted slice expira...

  • EPSS 3.46%
  • Veröffentlicht 22.12.2019 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:35:39

sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2018-11805.

Exploit
  • EPSS 1.02%
  • Veröffentlicht 20.12.2019 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:31:11

Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any pr...

  • EPSS 0.9%
  • Veröffentlicht 20.12.2019 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:31:11

Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-En...

Medienbericht
  • EPSS 37.54%
  • Veröffentlicht 20.12.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:32:33

Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic fo...

  • EPSS 0.69%
  • Veröffentlicht 20.12.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 01:45:48

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

  • EPSS 0.39%
  • Veröffentlicht 20.12.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 01:45:50

gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function

  • EPSS 0.08%
  • Veröffentlicht 20.12.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 01:40:48

ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation

  • EPSS 0.45%
  • Veröffentlicht 20.12.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 01:45:01

LibreOffice and OpenOffice automatically open embedded content

  • EPSS 1.06%
  • Veröffentlicht 20.12.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 02:38:16

GnuTLS incorrectly validates the first byte of padding in CBC modes