Debian

Debian Linux

9142 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 22.79%
  • Published 28.11.2013 04:37:39
  • Last modified 11.04.2025 00:51:21

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted inte...

  • EPSS 13.98%
  • Published 20.11.2013 14:12:30
  • Last modified 11.04.2025 00:51:21

lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple...

  • EPSS 7.81%
  • Published 20.11.2013 14:12:30
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.

  • EPSS 0.21%
  • Published 19.11.2013 04:50:56
  • Last modified 11.04.2025 00:51:21

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of s...

  • EPSS 13.22%
  • Published 18.11.2013 05:23:57
  • Last modified 11.04.2025 00:51:21

Integer overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013.

  • EPSS 5.86%
  • Published 18.11.2013 03:55:05
  • Last modified 11.04.2025 00:51:21

The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon ...

Exploit
  • EPSS 1.48%
  • Published 13.11.2013 15:55:04
  • Last modified 11.04.2025 00:51:21

Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the x-webkit-speech attribute in a text INPUT element.

  • EPSS 1.31%
  • Published 13.11.2013 15:55:03
  • Last modified 11.04.2025 00:51:21

Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file an...

Exploit
  • EPSS 2.91%
  • Published 08.11.2013 04:47:22
  • Last modified 11.04.2025 00:51:21

lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.

  • EPSS 0.28%
  • Published 05.11.2013 21:55:12
  • Last modified 11.04.2025 00:51:21

The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.