Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.83%
  • Veröffentlicht 13.11.2018 23:29:00
  • Zuletzt bearbeitet 21.11.2024 03:52:49

There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do no...

Exploit
  • EPSS 6.3%
  • Veröffentlicht 12.11.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:33

In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 12.11.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:34

Netwide Assembler (NASM) before 2.13.02 has a use-after-free in detoken at asm/preproc.c.

  • EPSS 2.36%
  • Veröffentlicht 12.11.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:33

steps/mail/func.inc in Roundcube before 1.3.8 has XSS via crafted use of <svg><style>, as demonstrated by an onload attribute in a BODY element, within an HTML attachment.

  • EPSS 0.68%
  • Veröffentlicht 12.11.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:32

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.

  • EPSS 0.7%
  • Veröffentlicht 12.11.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:32

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.

  • EPSS 1.12%
  • Veröffentlicht 12.11.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:32

An issue was discovered in uriparser before 0.9.0. UriCommon.c allows attempted operations on NULL input via a uriResetUri* function.

  • EPSS 0.27%
  • Veröffentlicht 11.11.2018 05:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:24

Open Ticket Request System (OTRS) 4.0.x before 4.0.33 and 5.0.x before 5.0.31 allows an admin to conduct an XSS attack via a modified URL because user and customer preferences are mishandled.

  • EPSS 0.13%
  • Veröffentlicht 11.11.2018 05:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:25

Open Ticket Request System (OTRS) 4.0.x before 4.0.33, 5.0.x before 5.0.31, and 6.0.x before 6.0.13 allows an authenticated user to delete files via a modified submission form because upload caching is mishandled.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 09.11.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:57:24

An issue has been found in JasPer 2.0.14. There is a memory leak in jas_malloc.c when called from jpc_unk_getparms in jpc_cs.c.