Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 07.02.2018 02:29:01
  • Zuletzt bearbeitet 21.11.2024 04:11:12

An issue was discovered in soliduiserver/deviceserviceaction.cpp in KDE Plasma Workspace before 5.12.0. When a vfat thumbdrive that contains `` or $() in its volume label is plugged in and mounted through the device notifier, it's interpreted as a sh...

Exploit
  • EPSS 0.88%
  • Veröffentlicht 06.02.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 04:11:08

A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly have unspecified other impact via a maliciously crafted RF64 file.

  • EPSS 9.26%
  • Veröffentlicht 06.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:03

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMappe...

  • EPSS 79.27%
  • Veröffentlicht 06.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:32:04

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the Obj...

  • EPSS 0.68%
  • Veröffentlicht 05.02.2018 04:29:00
  • Zuletzt bearbeitet 21.11.2024 04:11:00

The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) via a crafted AVI file.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 04.02.2018 22:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:59

In OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file.

  • EPSS 0.51%
  • Veröffentlicht 03.02.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:58

webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 03.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:23

The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.

Exploit
  • EPSS 0.8%
  • Veröffentlicht 03.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:10:57

lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only ...

  • EPSS 0.36%
  • Veröffentlicht 02.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:23

The consentAdmin module in SimpleSAMLphp through 1.14.15 is vulnerable to a Cross-Site Scripting attack, allowing an attacker to craft links that could execute arbitrary JavaScript code on the victim's web browser.