Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.5%
  • Veröffentlicht 14.02.2016 02:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extension behavior, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript cod...

  • EPSS 0.52%
  • Veröffentlicht 13.02.2016 02:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive inform...

  • EPSS 0.84%
  • Veröffentlicht 13.02.2016 02:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (mis...

Exploit
  • EPSS 1.86%
  • Veröffentlicht 13.02.2016 02:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based...

  • EPSS 0.75%
  • Veröffentlicht 13.02.2016 02:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary ...

  • EPSS 1.56%
  • Veröffentlicht 13.02.2016 02:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple memory leaks in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 allow remote authenticated users to cause a denial of service (memory consumption) via a request specifying a NULL pr...

  • EPSS 0.68%
  • Veröffentlicht 13.02.2016 02:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verify whether '\0' characters exist as expected, which allows remote authenticated users to obtain sensit...

  • EPSS 1.32%
  • Veröffentlicht 12.02.2016 15:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.

  • EPSS 0.82%
  • Veröffentlicht 12.02.2016 05:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PTS (aka presentation timestamp) value in a ...

  • EPSS 56.23%
  • Veröffentlicht 08.02.2016 03:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and us...