Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.06%
  • Veröffentlicht 27.07.2018 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:42:13

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound write in in fs/jbd2/transaction.c code, a denial of service, and a system crash by unmounting a crafted ext4 filesystem image.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 27.07.2018 18:29:00
  • Zuletzt bearbeitet 29.08.2025 13:42:30

It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies. If the cookie is correct, it is allowed to attach to the Xorg session. Since most memcmp() implementations ret...

  • EPSS 0.95%
  • Veröffentlicht 27.07.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:53

An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.

  • EPSS 1.55%
  • Veröffentlicht 27.07.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:06

The Network Block Device (NBD) server in Quick Emulator (QEMU) before 2.11 is vulnerable to a denial of service issue. It could occur if a client sent large option requests, making the server waste CPU time on reading up to 4GB per request. A client ...

  • EPSS 0.33%
  • Veröffentlicht 27.07.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:06

An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An unauthenticated remot...

  • EPSS 5.97%
  • Veröffentlicht 27.07.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:56

It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.

  • EPSS 1.39%
  • Veröffentlicht 27.07.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:56

It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 27.07.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:32:03

In Ceph, a format string flaw was found in the way libradosstriper parses input from user. A user could crash an application or service using the libradosstriper library.

  • EPSS 4.15%
  • Veröffentlicht 27.07.2018 12:29:00
  • Zuletzt bearbeitet 21.11.2024 03:08:56

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attac...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 27.07.2018 04:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:24

An issue was discovered in the Linux kernel through 4.17.10. There is an invalid pointer dereference in __del_reloc_root() in fs/btrfs/relocation.c when mounting a crafted btrfs image, related to removing reloc rb_trees when reloc control has not bee...