Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.35%
  • Veröffentlicht 10.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:06:08

An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disc...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 10.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:06:08

An exploitable information vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds read on the heap, resulting in information disclosure. An ...

Exploit
  • EPSS 1.16%
  • Veröffentlicht 10.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:06:08

An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An atta...

  • EPSS 0.65%
  • Veröffentlicht 10.04.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:59

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.

  • EPSS 0.4%
  • Veröffentlicht 10.04.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:59

ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 09.04.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:24:13

An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in informat...

  • EPSS 5.78%
  • Veröffentlicht 09.04.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:35

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` parameter of Solr's DataImportHandler. It can be used as XXE using file/ftp/http protocols in order t...

  • EPSS 1.01%
  • Veröffentlicht 07.04.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:15:47

In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled "_uid" parameter (in an archive.php _task=mail&_mbox=INBOX&_action=plugin.move2archive request) to pe...

  • EPSS 36.76%
  • Veröffentlicht 06.04.2018 13:29:00
  • Zuletzt bearbeitet 14.04.2025 20:15:16

GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via th...

  • EPSS 89.95%
  • Veröffentlicht 06.04.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:30

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A ma...