Debian

Debian Linux

9213 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.57%
  • Veröffentlicht 08.04.2019 19:29:05
  • Zuletzt bearbeitet 21.11.2024 04:37:22

A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected de...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 07.04.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:19:49

In KDE KMail 5.2.3, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipa...

Exploit
  • EPSS 0.63%
  • Veröffentlicht 06.04.2019 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:06

Roundup 1.6 allows XSS via the URI because frontends/roundup.cgi and roundup/cgi/wsgi_handler.py mishandle 404 errors.

  • EPSS 0.28%
  • Veröffentlicht 05.04.2019 01:29:00
  • Zuletzt bearbeitet 21.11.2024 04:20:00

In trytond/model/modelstorage.py in Tryton 4.2 before 4.2.21, 4.4 before 4.4.19, 4.6 before 4.6.14, 4.8 before 4.8.10, and 5.0 before 5.0.6, an authenticated user can order records based on a field for which he has no access right. This may allow the...

  • EPSS 0.41%
  • Veröffentlicht 04.04.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:41:05

Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.

Exploit
  • EPSS 0.58%
  • Veröffentlicht 30.03.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:19:40

In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 30.03.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:19:40

In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or information disclosure via a crafted image file.

  • EPSS 11.84%
  • Veröffentlicht 28.03.2019 22:29:00
  • Zuletzt bearbeitet 21.11.2024 04:16:31

In Apache ActiveMQ 5.0.0 - 5.15.8, unmarshalling corrupt MQTT frame can lead to broker Out of Memory exception making it unresponsive.

  • EPSS 0.03%
  • Veröffentlicht 28.03.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:48:16

In Dovecot before 2.2.36.3 and 2.3.x before 2.3.5.1, a local attacker can cause a buffer overflow in the indexer-worker process, which can be used to elevate to root. This occurs because of missing checks in the fts and pop3-uidl components.

  • EPSS 0.83%
  • Veröffentlicht 27.03.2019 20:29:02
  • Zuletzt bearbeitet 21.11.2024 03:32:23

In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those applications using the library.