Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 13.04.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:01:34

ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572), which can be abused to lead to commit metadata forgery.

Exploit
  • EPSS 5.62%
  • Veröffentlicht 13.04.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:02:49

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via repeated parameters.

  • EPSS 1.6%
  • Veröffentlicht 13.04.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:02:49

A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.

Exploit
  • EPSS 7.55%
  • Veröffentlicht 13.04.2018 15:29:00
  • Zuletzt bearbeitet 04.12.2025 16:15:48

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege esca...

  • EPSS 0.08%
  • Veröffentlicht 13.04.2018 13:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:47

The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering an attempted use of the -INT_MIN value.

  • EPSS 0.31%
  • Veröffentlicht 12.04.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:08

corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c.

Exploit
  • EPSS 0.67%
  • Veröffentlicht 12.04.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:44

Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.

Exploit
  • EPSS 0.96%
  • Veröffentlicht 12.04.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:44

Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).

  • EPSS 0.2%
  • Veröffentlicht 12.04.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:09

pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote att...

  • EPSS 0.98%
  • Veröffentlicht 11.04.2018 03:29:00
  • Zuletzt bearbeitet 21.11.2024 03:40:40

The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.