Debian

Debian Linux

9213 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 5.51%
  • Veröffentlicht 17.12.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:55:34

Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.

  • EPSS 0.1%
  • Veröffentlicht 17.12.2018 07:29:00
  • Zuletzt bearbeitet 21.11.2024 04:01:00

An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c.

Medienbericht
  • EPSS 5.79%
  • Veröffentlicht 14.12.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:56

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could modify metadata to bypass intended restrictions on deleting files.

Medienbericht Exploit
  • EPSS 54.86%
  • Veröffentlicht 14.12.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:56

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_t...

Medienbericht
  • EPSS 4.43%
  • Veröffentlicht 14.12.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:57

In WordPress before 4.9.9 and 5.x before 5.0.1, when the Apache HTTP Server is used, authors could upload crafted files that bypass intended MIME type restrictions, leading to XSS, as demonstrated by a .jpg file without JPEG data.

Medienbericht
  • EPSS 7.37%
  • Veröffentlicht 14.12.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:57

In WordPress before 4.9.9 and 5.x before 5.0.1, crafted URLs could trigger XSS for certain use cases involving plugins.

Medienbericht
  • EPSS 6.8%
  • Veröffentlicht 14.12.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:57

In WordPress before 4.9.9 and 5.x before 5.0.1, the user-activation page could be read by a search engine's web crawler if an unusual configuration were chosen. The search engine could then index and display a user's e-mail address and (rarely) the p...

Medienbericht
  • EPSS 11.68%
  • Veröffentlicht 14.12.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:57

In WordPress before 4.9.9 and 5.x before 5.0.1, authors could bypass intended restrictions on post types via crafted input.

Medienbericht
  • EPSS 5.38%
  • Veröffentlicht 14.12.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:00:57

In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could modify new comments made by users with greater privileges, possibly causing XSS.

  • EPSS 63.39%
  • Veröffentlicht 14.12.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:29

In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically,...