Debian

Debian Linux

9142 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.1%
  • Published 17.07.2014 05:10:14
  • Last modified 12.04.2025 10:46:40

Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.

Exploit
  • EPSS 1.01%
  • Published 09.07.2014 11:07:03
  • Last modified 12.04.2025 10:46:40

The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain p...

  • EPSS 8.85%
  • Published 09.07.2014 11:07:01
  • Last modified 12.04.2025 10:46:40

The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, allows remote attackers to cause a denial of service (assertion failure and application exit) via a craft...

  • EPSS 11.28%
  • Published 09.07.2014 11:07:01
  • Last modified 12.04.2025 10:46:40

The cdf_check_stream_offset function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, relies on incorrect sector-size data, which allows remote attackers to cause a denial of service (appli...

  • EPSS 11.28%
  • Published 09.07.2014 11:07:01
  • Last modified 12.04.2025 10:46:40

The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate sector-count data, which allows remote attackers to cause a denial of service (appli...

  • EPSS 18.5%
  • Published 09.07.2014 11:07:01
  • Last modified 12.04.2025 10:46:40

The cdf_read_property_info function in file before 5.19, as used in the Fileinfo component in PHP before 5.4.30 and 5.5.x before 5.5.14, does not properly validate a stream offset, which allows remote attackers to cause a denial of service (applicati...

  • EPSS 37.41%
  • Published 09.07.2014 11:07:01
  • Last modified 12.04.2025 10:46:40

The SPL component in PHP before 5.4.30 and 5.5.x before 5.5.14 incorrectly anticipates that certain data structures will have the array data type after unserialization, which allows remote attackers to execute arbitrary code via a crafted string that...

Exploit
  • EPSS 9.94%
  • Published 06.07.2014 23:55:02
  • Last modified 12.04.2025 10:46:40

The phpinfo implementation in ext/standard/info.c in PHP before 5.4.30 and 5.5.x before 5.5.14 does not ensure use of the string data type for the PHP_AUTH_PW, PHP_AUTH_TYPE, PHP_AUTH_USER, and PHP_SELF variables, which might allow context-dependent ...

Exploit
  • EPSS 10.25%
  • Published 03.07.2014 14:55:07
  • Last modified 12.04.2025 10:46:40

file before 5.19 does not properly restrict the amount of data read during a regex search, which allows remote attackers to cause a denial of service (CPU consumption) via a crafted file that triggers backtracking during processing of an awk rule. N...

  • EPSS 14.14%
  • Published 03.07.2014 04:22:16
  • Last modified 12.04.2025 10:46:40

The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.