Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 13.06.2018 16:29:01
  • Zuletzt bearbeitet 21.11.2024 03:43:18

The security handlers in the Security component in Symfony in 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11 have an Open redirect vulnerability when security.http_utils is inlined by a con...

  • EPSS 0.05%
  • Veröffentlicht 13.06.2018 16:29:01
  • Zuletzt bearbeitet 21.11.2024 03:44:04

m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.

  • EPSS 0.22%
  • Veröffentlicht 13.06.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:16:46

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and ...

  • EPSS 0.9%
  • Veröffentlicht 13.06.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:16

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an a...

  • EPSS 1.09%
  • Veröffentlicht 13.06.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:16

An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. U...

  • EPSS 0.18%
  • Veröffentlicht 13.06.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:43:17

An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This be...

Exploit
  • EPSS 0.73%
  • Veröffentlicht 13.06.2018 11:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:53

Exiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in Exiv2::ValueType::setDataArea in value.hpp.

Exploit
  • EPSS 0.73%
  • Veröffentlicht 13.06.2018 11:29:00
  • Zuletzt bearbeitet 21.11.2024 03:44:53

Exiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in basicio.cpp.

  • EPSS 0.53%
  • Veröffentlicht 12.06.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:21

Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system.

  • EPSS 0.15%
  • Veröffentlicht 12.06.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:32

In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS...