Debian

Debian Linux

9928 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.74%
  • Veröffentlicht 26.06.2019 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:02:18

An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can lead to an integer overflow.

  • EPSS 0.05%
  • Veröffentlicht 26.06.2019 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:55

In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.

  • EPSS 0.13%
  • Veröffentlicht 26.06.2019 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:56

ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 26.06.2019 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:56

ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.

  • EPSS 0.21%
  • Veröffentlicht 26.06.2019 18:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:56

ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c.

  • EPSS 0.41%
  • Veröffentlicht 26.06.2019 14:15:09
  • Zuletzt bearbeitet 12.09.2025 19:44:04

Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user...

  • EPSS 0.07%
  • Veröffentlicht 25.06.2019 12:15:11
  • Zuletzt bearbeitet 21.11.2024 04:23:38

arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of pow...

Exploit
  • EPSS 5.83%
  • Veröffentlicht 24.06.2019 17:15:09
  • Zuletzt bearbeitet 30.05.2025 20:15:20

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amount of RAM and CPU resources while processing (enough to be usable for denial-of-service attacks).

  • EPSS 51.68%
  • Veröffentlicht 24.06.2019 16:15:15
  • Zuletzt bearbeitet 21.11.2024 04:22:43

FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be ...

  • EPSS 1.13%
  • Veröffentlicht 19.06.2019 23:15:09
  • Zuletzt bearbeitet 09.06.2025 16:15:29

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.