Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 13.04.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:02:51

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw were Spam blacklist is ineffective on encoded URLs inside file inclusion syntax's link parameter.

Exploit
  • EPSS 58.35%
  • Veröffentlicht 13.04.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:02:51

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

  • EPSS 0.26%
  • Veröffentlicht 13.04.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:01:34

ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.

Exploit
  • EPSS 5.62%
  • Veröffentlicht 13.04.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:02:49

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.

  • EPSS 1.6%
  • Veröffentlicht 13.04.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:02:49

A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.

Exploit
  • EPSS 7.55%
  • Veröffentlicht 13.04.2018 15:29:00
  • Zuletzt bearbeitet 04.12.2025 16:15:48

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege esca...

  • EPSS 0.08%
  • Veröffentlicht 13.04.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:47

The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of the -INT_MIN value.

  • EPSS 0.31%
  • Veröffentlicht 12.04.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:08

corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 12.04.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:44

Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.

Exploit
  • EPSS 0.96%
  • Veröffentlicht 12.04.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:44

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).