Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.36%
  • Veröffentlicht 17.07.2018 03:29:00
  • Zuletzt bearbeitet 21.11.2024 03:48:51

The CHECK macro in mrbgems/mruby-sprintf/src/sprintf.c in mruby 1.4.1 contains a signed integer overflow, possibly leading to out-of-bounds memory access because the mrb_str_resize function in string.c does not check for a negative length.

  • EPSS 0.5%
  • Veröffentlicht 16.07.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:09

git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.

Exploit
  • EPSS 25.19%
  • Veröffentlicht 16.07.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:45:29

The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denial of service (buffer overflow) or possibly execute arbitrary code when TLS communication is enabled.

  • EPSS 0.5%
  • Veröffentlicht 16.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:09

git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could be used to expose encrypted dat...

  • EPSS 1.09%
  • Veröffentlicht 16.07.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:03

ClamAV before 0.100.1 has an HWP integer overflow with a resultant infinite loop via a crafted Hangul Word Processor file. This is in parsehwp3_paragraph() in libclamav/hwp.c.

  • EPSS 0.64%
  • Veröffentlicht 16.07.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:03

ClamAV before 0.100.1 lacks a PDF object length check, resulting in an unreasonably long time to parse a relatively small file.

  • EPSS 0.07%
  • Veröffentlicht 16.07.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 02:05:36

X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.

  • EPSS 0.38%
  • Veröffentlicht 15.07.2018 01:29:03
  • Zuletzt bearbeitet 21.11.2024 03:48:31

ZNC before 1.7.1-rc1 does not properly validate untrusted lines coming from the network, allowing a non-admin user to escalate his privilege and inject rogue values into znc.conf.

  • EPSS 0.69%
  • Veröffentlicht 15.07.2018 01:29:03
  • Zuletzt bearbeitet 21.11.2024 03:48:32

ZNC before 1.7.1-rc1 is prone to a path traversal flaw via ../ in a web skin name to access files outside of the intended skins directories.

  • EPSS 0.04%
  • Veröffentlicht 13.07.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:11

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.