Debian

Debian Linux

9140 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 30.11.2007 01:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x before B.2.3.4, and C.x before C.1.0-beta6 allows remote authenticated users to execute arbitrary SQL ...

  • EPSS 0.04%
  • Veröffentlicht 30.10.2007 22:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" int...

  • EPSS 0.15%
  • Veröffentlicht 30.10.2007 22:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" hea...

  • EPSS 0.14%
  • Veröffentlicht 30.10.2007 22:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used ...

  • EPSS 41.63%
  • Veröffentlicht 11.10.2007 10:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemo...

  • EPSS 0.1%
  • Veröffentlicht 04.10.2007 16:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.

  • EPSS 12.96%
  • Veröffentlicht 18.09.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which...

  • EPSS 11.81%
  • Veröffentlicht 05.09.2007 01:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."

  • EPSS 2.25%
  • Veröffentlicht 04.09.2007 22:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn func...

  • EPSS 7.29%
  • Veröffentlicht 04.09.2007 18:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certai...