Debian

Debian Linux

9141 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.51%
  • Veröffentlicht 07.07.2011 21:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSS...

  • EPSS 8.08%
  • Veröffentlicht 06.06.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as e...

  • EPSS 6.7%
  • Veröffentlicht 06.06.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x and 1.6.x before 1.6.17, when the SVNPathAuthz short_circuit option is enabled, allows remote attackers to cause a denial of service (infinite loop and memor...

  • EPSS 0.61%
  • Veröffentlicht 16.05.2011 17:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Google Chrome before 11.0.696.68 does not properly perform casts of variables during interaction with the WebKit engine, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

Exploit
  • EPSS 56.21%
  • Veröffentlicht 16.05.2011 17:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac...

Exploit
  • EPSS 2.48%
  • Veröffentlicht 03.05.2011 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in Google Chrome before 11.0.696.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the ruby element and Cascading Style Sheets (CSS) token sequences.

Exploit
  • EPSS 0.69%
  • Veröffentlicht 03.05.2011 22:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Race condition in the sandbox launcher implementation in Google Chrome before 11.0.696.57 on Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • EPSS 0.78%
  • Veröffentlicht 29.04.2011 22:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy...

  • EPSS 71.99%
  • Veröffentlicht 08.04.2011 15:17:27
  • Zuletzt bearbeitet 11.04.2025 00:51:21

dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstra...

  • EPSS 1.3%
  • Veröffentlicht 29.03.2011 18:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, whic...