Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Exploit
  • EPSS 94.49%
  • Veröffentlicht 29.03.2018 07:29:00
  • Zuletzt bearbeitet 31.10.2025 22:05:42

Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations.

  • EPSS 1.42%
  • Veröffentlicht 28.03.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:06

libvirt version before 4.2.0-rc1 is vulnerable to a resource exhaustion as a result of an incomplete fix for CVE-2018-5748 that affects QEMU monitor but now also triggered via QEMU guest agent.

Exploit
  • EPSS 10.89%
  • Veröffentlicht 28.03.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:07:54

An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing a malformed SQL statement.

  • EPSS 0.09%
  • Veröffentlicht 28.03.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:08

Zsh before version 5.4.2-test-1 is vulnerable to a buffer overflow in the shell autocomplete functionality. A local unprivileged user can create a specially crafted directory path which leads to code execution in the context of the user who tries to ...

  • EPSS 14.45%
  • Veröffentlicht 27.03.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:50

Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used w...

  • EPSS 0.69%
  • Veröffentlicht 27.03.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:13:11

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

Exploit
  • EPSS 0.45%
  • Veröffentlicht 27.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:14:15

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 has XSS via the dn parameter to the templates/3rdParty/pla/htdocs/cmd.php URI or the template parameter to the templates/3rdParty/pla/htdocs/cmd.php?cmd=rename_form URI.

Exploit
  • EPSS 0.36%
  • Veröffentlicht 27.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:14:16

Roland Gruber Softwareentwicklung LDAP Account Manager before 6.3 places a CSRF token in the sec_token parameter of a URI, which makes it easier for remote attackers to defeat a CSRF protection mechanism by leveraging logging.

  • EPSS 2.18%
  • Veröffentlicht 27.03.2018 09:29:00
  • Zuletzt bearbeitet 21.11.2024 03:37:43

clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input validation checking mechanis...

  • EPSS 0.06%
  • Veröffentlicht 26.03.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:40

The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, which allows local users to cause a denial of service (race condition) or possibly have unspecified other impact via concurrent thre...