Debian

Debian Linux

9140 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.76%
  • Veröffentlicht 05.11.2008 15:00:14
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (syste...

  • EPSS 1.09%
  • Veröffentlicht 30.10.2008 20:56:54
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitra...

  • EPSS 35.58%
  • Veröffentlicht 15.10.2008 20:08:02
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the...

  • EPSS 0.51%
  • Veröffentlicht 03.10.2008 17:41:40
  • Zuletzt bearbeitet 09.04.2025 00:30:58

lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive inform...

  • EPSS 1.14%
  • Veröffentlicht 03.10.2008 17:41:40
  • Zuletzt bearbeitet 09.04.2025 00:30:58

mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access r...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 29.09.2008 17:17:29
  • Zuletzt bearbeitet 09.04.2025 00:30:58

fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a deni...

  • EPSS 2.56%
  • Veröffentlicht 24.09.2008 20:37:04
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted...

  • EPSS 2.43%
  • Veröffentlicht 24.09.2008 20:37:04
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vec...

  • EPSS 2.72%
  • Veröffentlicht 24.09.2008 20:37:04
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) ...

  • EPSS 2.03%
  • Veröffentlicht 24.09.2008 20:37:04
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or po...