Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 28.09.2018 00:29:02
  • Zuletzt bearbeitet 21.11.2024 03:53:00

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a user with admin permissions opens it, it causes deletions of arbitrary files that...

  • EPSS 0.58%
  • Veröffentlicht 28.09.2018 00:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:59

In Open Ticket Request System (OTRS) 4.0.x before 4.0.32, 5.0.x before 5.0.30, and 6.0.x before 6.0.11, an attacker could send a malicious email to an OTRS system. If a logged in user opens it, the email could cause the browser to load external image...

  • EPSS 1.69%
  • Veröffentlicht 26.09.2018 21:29:01
  • Zuletzt bearbeitet 03.12.2025 21:15:50

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data after the encoded algorithm OID during PKCS#1 v1.5 signature verificati...

  • EPSS 1.69%
  • Veröffentlicht 26.09.2018 21:29:01
  • Zuletzt bearbeitet 03.12.2025 21:15:50

In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation based on GMP does not reject excess data in the digestAlgorithm.parameters field during PKCS#1 v1.5 signature ve...

  • EPSS 1.37%
  • Veröffentlicht 25.09.2018 14:29:04
  • Zuletzt bearbeitet 21.11.2024 04:09:58

Use after free in WebUI in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.

  • EPSS 0.69%
  • Veröffentlicht 25.09.2018 14:29:03
  • Zuletzt bearbeitet 21.11.2024 04:09:57

Incorrect security UI in permissions prompt in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the origin to which permission is granted via a crafted HTML page.

  • EPSS 0.91%
  • Veröffentlicht 25.09.2018 14:29:03
  • Zuletzt bearbeitet 21.11.2024 04:09:57

Incorrect security UI in Omnibox in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • EPSS 0.57%
  • Veröffentlicht 25.09.2018 14:29:03
  • Zuletzt bearbeitet 21.11.2024 04:09:57

XSS Auditor in Google Chrome prior to 64.0.3282.119, did not ensure the reporting URL was in the same origin as the page it was on, which allowed a remote attacker to obtain referrer details via a crafted HTML page.

  • EPSS 0.84%
  • Veröffentlicht 25.09.2018 14:29:03
  • Zuletzt bearbeitet 21.11.2024 04:09:58

Lack of support for a non standard no-referrer policy value in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain referrer details from a web page that had thought it had opted out of sending referrer data.

  • EPSS 0.17%
  • Veröffentlicht 25.09.2018 14:29:03
  • Zuletzt bearbeitet 21.11.2024 04:09:58

Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.