Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.55%
  • Veröffentlicht 03.12.2017 07:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send ...

  • EPSS 0.82%
  • Veröffentlicht 03.12.2017 07:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory aut...

  • EPSS 1%
  • Veröffentlicht 03.12.2017 07:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can cause a denial of service (application hang) via crafted PEM input that signifies a public key requir...

  • EPSS 0.3%
  • Veröffentlicht 03.12.2017 07:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradatio...

  • EPSS 0.67%
  • Veröffentlicht 03.12.2017 07:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged i...

  • EPSS 3.31%
  • Veröffentlicht 02.12.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

  • EPSS 6.28%
  • Veröffentlicht 02.12.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.

  • EPSS 6.62%
  • Veröffentlicht 02.12.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

wp-includes/feed.php in WordPress before 4.9.1 does not properly restrict enclosures in RSS and Atom fields, which might allow attackers to conduct XSS attacks via a crafted URL.

  • EPSS 0.06%
  • Veröffentlicht 01.12.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be triggered by opening files.

Exploit
  • EPSS 3.56%
  • Veröffentlicht 01.12.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack vector exists against the related code in cursor/xcur...