Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.74%
  • Veröffentlicht 14.03.2018 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:13:15

Integer overflow in the index.c:read_entry() function while decompressing a compressed prefix length in libgit2 before v0.26.2 allows an attacker to cause a denial of service (out-of-bounds read) via a crafted repository index file.

  • EPSS 0.95%
  • Veröffentlicht 14.03.2018 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:13:15

Incorrect returning of an error code in the index.c:read_entry() function leads to a double free in libgit2 before v0.26.2, which allows an attacker to cause a denial of service via a crafted repository index file.

  • EPSS 1%
  • Veröffentlicht 13.03.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 03:39:44

memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused from free list. This attack appear to be exploitable...

Exploit
  • EPSS 20.05%
  • Veröffentlicht 13.03.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:12:39

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is co...

  • EPSS 25.96%
  • Veröffentlicht 13.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:04

All versions of Samba from 4.0.0 onwards are vulnerable to a denial of service attack when the RPC spoolss service is configured to be run as an external daemon. Missing input sanitization checks on some of the input parameters to spoolss RPC calls c...

  • EPSS 6.72%
  • Veröffentlicht 13.03.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:59:05

On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privi...

  • EPSS 0.95%
  • Veröffentlicht 13.03.2018 15:29:01
  • Zuletzt bearbeitet 21.11.2024 03:39:36

ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The ...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 13.03.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:39:34

FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind ...

  • EPSS 1.76%
  • Veröffentlicht 13.03.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:39:34

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerabil...

  • EPSS 0.93%
  • Veröffentlicht 13.03.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:39:35

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Improper Verification of Cryptographic Signature...