Debian

Debian Linux

9213 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 10.91%
  • Veröffentlicht 30.01.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:02:05

LibVNC before 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Exploit
  • EPSS 10.91%
  • Veröffentlicht 30.01.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:02:05

LibVNC through 0.9.12 contains a heap out-of-bounds write vulnerability in libvncserver/rfbserver.c. The fix for CVE-2018-15127 was incomplete.

Exploit
  • EPSS 0.34%
  • Veröffentlicht 29.01.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:47:39

A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by eu-nm.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 29.01.2019 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:47:40

An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted inp...

  • EPSS 7.37%
  • Veröffentlicht 28.01.2019 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:42:05

Incorrect sanitation of the 302 redirect field in HTTP transport method of apt versions 1.4.8 and earlier can lead to content injection by a MITM attacker, potentially leading to remote code execution on the target machine.

  • EPSS 0.14%
  • Veröffentlicht 28.01.2019 15:29:00
  • Zuletzt bearbeitet 21.11.2024 04:42:35

A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A...

  • EPSS 3.68%
  • Veröffentlicht 28.01.2019 08:29:00
  • Zuletzt bearbeitet 21.11.2024 04:47:21

The GD Graphics Library (aka LibGD) 2.2.5 has a double free in the gdImage*Ptr() functions in gd_gif_out.c, gd_jpeg.c, and gd_wbmp.c. NOTE: PHP is unaffected.

Exploit
  • EPSS 89.15%
  • Veröffentlicht 27.01.2019 02:29:00
  • Zuletzt bearbeitet 21.11.2024 04:47:20

gdImageColorMatch in gd_color_match.c in the GD Graphics Library (aka LibGD) 2.2.5, as used in the imagecolormatch function in PHP before 5.6.40, 7.x before 7.1.26, 7.2.x before 7.2.14, and 7.3.x before 7.3.1, has a heap-based buffer overflow. This c...

  • EPSS 70.65%
  • Veröffentlicht 26.01.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:47:10

An issue was discovered in phpMyAdmin before 4.8.5. When the AllowArbitraryServer configuration setting is set to true, with the use of a rogue MySQL server, an attacker can read any file on the server that the web server's user can access. This is r...

  • EPSS 2.77%
  • Veröffentlicht 25.01.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:53:31

A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.