Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 87.61%
  • Veröffentlicht 16.01.2018 09:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:13

An issue was discovered in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. There is Reflected XSS on the PHAR 404 error page via the URI of a request for a .phar file.

Exploit
  • EPSS 27.22%
  • Veröffentlicht 15.01.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 04:09:12

Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST request...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 14.01.2018 02:29:05
  • Zuletzt bearbeitet 21.11.2024 04:09:09

In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with a crafted bit-field mask valu...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 14.01.2018 02:29:05
  • Zuletzt bearbeitet 21.11.2024 04:09:10

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a craft...

  • EPSS 0.92%
  • Veröffentlicht 13.01.2018 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:38:19

Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct im...

  • EPSS 0.93%
  • Veröffentlicht 12.01.2018 23:29:01
  • Zuletzt bearbeitet 21.11.2024 03:11:08

A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-64710201.

  • EPSS 0.75%
  • Veröffentlicht 12.01.2018 00:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:37

A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file.

  • EPSS 0.87%
  • Veröffentlicht 11.01.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:36

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.

  • EPSS 0.87%
  • Veröffentlicht 11.01.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:36

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the WCP dissector could crash. This was addressed in epan/dissectors/packet-wcp.c by validating the available buffer length.

  • EPSS 1.01%
  • Veröffentlicht 11.01.2018 21:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:36

In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the JSON, XML, NTP, XMPP, and GDB dissectors could crash. This was addressed in epan/tvbparse.c by limiting the recursion depth.