Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.42%
  • Veröffentlicht 23.11.2022 21:15:11
  • Zuletzt bearbeitet 25.04.2025 20:15:35

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 23.11.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:07

pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `PreparedStatemet.setBytea(int, InputStream)` will create a temporary file if the InputStream is ...

  • EPSS 0.46%
  • Veröffentlicht 22.11.2022 02:15:11
  • Zuletzt bearbeitet 21.11.2024 07:12:37

In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476...

  • EPSS 0.15%
  • Veröffentlicht 18.11.2022 21:15:11
  • Zuletzt bearbeitet 29.04.2025 19:15:52

In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials can submit crafted XMLRPC requests that cause a recursive XML entity expansion, leading to excessive use of memory on the server and a Denial of Service.

  • EPSS 0.23%
  • Veröffentlicht 15.11.2022 23:15:27
  • Zuletzt bearbeitet 21.11.2024 07:24:03

Heimdal is an implementation of ASN.1/DER, PKIX, and Kerberos. Versions prior to 7.7.1 are vulnerable to a denial of service vulnerability in Heimdal's PKI certificate validation library, affecting the KDC (via PKINIT) and kinit (via PKINIT), as well...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 13.11.2022 08:15:16
  • Zuletzt bearbeitet 21.11.2024 07:20:38

A vulnerability was found in LibTIFF. It has been classified as critical. This affects the function TIFFReadRGBATileExt of the file libtiff/tif_getimage.c. The manipulation leads to integer overflow. It is possible to initiate the attack remotely. Th...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 12.11.2022 05:15:12
  • Zuletzt bearbeitet 21.11.2024 07:28:55

Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).

  • EPSS 0.89%
  • Veröffentlicht 09.11.2022 07:15:10
  • Zuletzt bearbeitet 01.05.2025 15:15:58

In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

  • EPSS 0.76%
  • Veröffentlicht 09.11.2022 06:15:09
  • Zuletzt bearbeitet 01.05.2025 15:15:58

An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request...

  • EPSS 0.22%
  • Veröffentlicht 09.11.2022 04:15:10
  • Zuletzt bearbeitet 21.11.2024 07:20:26

Use after free in Speech Recognition in Google Chrome prior to 107.0.5304.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)