Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.91%
  • Veröffentlicht 04.12.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:10:04

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • EPSS 0.91%
  • Veröffentlicht 04.12.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:10:04

Incorrect handling of confusable characters in Omnibox in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • EPSS 0.91%
  • Veröffentlicht 04.12.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:10:04

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • EPSS 0.91%
  • Veröffentlicht 04.12.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:10:05

Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted HTML page.

  • EPSS 1.52%
  • Veröffentlicht 04.12.2018 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:10:06

A nullptr dereference in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • EPSS 2.4%
  • Veröffentlicht 04.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:01

Re-entry of a destructor in Networking Disk Cache in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 04.12.2018 09:29:00
  • Zuletzt bearbeitet 21.11.2024 03:58:40

The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvun...

  • EPSS 0.06%
  • Veröffentlicht 03.12.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:58:37

In the Linux kernel through 4.19.6, a local user could exploit a use-after-free in the ALSA driver by supplying a malicious USB Sound device (with zero interfaces) that is mishandled in usb_audio_probe in sound/usb/card.c.

Exploit
  • EPSS 59.64%
  • Veröffentlicht 03.12.2018 06:29:00
  • Zuletzt bearbeitet 21.11.2024 03:58:33

A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

  • EPSS 0.53%
  • Veröffentlicht 02.12.2018 10:29:00
  • Zuletzt bearbeitet 18.12.2025 16:15:46

An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by "j a v a s c r i p t:" in Interne...