Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.59%
  • Veröffentlicht 29.08.2018 13:29:01
  • Zuletzt bearbeitet 21.11.2024 04:13:04

There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upg...

  • EPSS 6.69%
  • Veröffentlicht 29.08.2018 13:29:01
  • Zuletzt bearbeitet 21.11.2024 04:13:04

When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the entire object from cache. This can cause performance problems with large objects in cache. This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolv...

  • EPSS 0.09%
  • Veröffentlicht 29.08.2018 03:29:00
  • Zuletzt bearbeitet 21.11.2024 03:52:01

dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.

  • EPSS 1.79%
  • Veröffentlicht 28.08.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:37

A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption ...

  • EPSS 9.05%
  • Veröffentlicht 28.08.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.

  • EPSS 30.45%
  • Veröffentlicht 28.08.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:38

A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • EPSS 0.73%
  • Veröffentlicht 28.08.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:41

Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

  • EPSS 0.66%
  • Veröffentlicht 28.08.2018 19:29:14
  • Zuletzt bearbeitet 21.11.2024 03:14:40

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.

  • EPSS 0.37%
  • Veröffentlicht 28.08.2018 19:29:14
  • Zuletzt bearbeitet 21.11.2024 03:14:40

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a socially engineered user to XSS themselves by dragging and dropping a javascript: URL into the URL bar.

  • EPSS 0.66%
  • Veröffentlicht 28.08.2018 19:29:13
  • Zuletzt bearbeitet 21.11.2024 03:14:40

Insufficient policy enforcement in Omnibox in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name.