Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.14%
  • Veröffentlicht 15.02.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:11:34

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. When the number of windows exceeds the available space, a crash due to a NULL pointer dereference would occur.

  • EPSS 0.82%
  • Veröffentlicht 15.02.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:11:34

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when SASL messages are received in an unexpected order.

  • EPSS 0.81%
  • Veröffentlicht 15.02.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 04:11:34

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. There is a use-after-free when a server is disconnected during netsplits. NOTE: this issue exists because of an incomplete fix for CVE-2017-7191.

Exploit
  • EPSS 5.71%
  • Veröffentlicht 15.02.2018 10:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:31

In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.

  • EPSS 0.42%
  • Veröffentlicht 14.02.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:19:30

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.

  • EPSS 4.87%
  • Veröffentlicht 13.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:20

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification w...

  • EPSS 3.56%
  • Veröffentlicht 13.02.2018 15:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:20

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within ...

  • EPSS 0.03%
  • Veröffentlicht 12.02.2018 19:29:01
  • Zuletzt bearbeitet 21.11.2024 04:11:26

The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact by triggering a negative wake or requeue value.

  • EPSS 0.65%
  • Veröffentlicht 09.02.2018 23:29:01
  • Zuletzt bearbeitet 21.11.2024 03:39:30

GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers thro...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 09.02.2018 23:29:01
  • Zuletzt bearbeitet 21.11.2024 03:39:31

Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.