Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.37%
  • Veröffentlicht 13.04.2016 16:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.

  • EPSS 0.27%
  • Veröffentlicht 13.04.2016 16:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.

Exploit
  • EPSS 0.68%
  • Veröffentlicht 13.04.2016 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers ...

  • EPSS 0.16%
  • Veröffentlicht 13.04.2016 15:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption)...

  • EPSS 0.07%
  • Veröffentlicht 13.04.2016 15:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) ...

Exploit
  • EPSS 2.73%
  • Veröffentlicht 13.04.2016 15:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and appl...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 13.04.2016 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.

  • EPSS 0.13%
  • Veröffentlicht 13.04.2016 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.

  • EPSS 78.65%
  • Veröffentlicht 12.04.2016 23:59:37
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersona...

  • EPSS 8.22%
  • Veröffentlicht 12.04.2016 15:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.