Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.19%
  • Veröffentlicht 11.12.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.

  • EPSS 0.95%
  • Veröffentlicht 11.12.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.

  • EPSS 0.95%
  • Veröffentlicht 11.12.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.

Exploit
  • EPSS 0.98%
  • Veröffentlicht 11.12.2017 02:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage.

  • EPSS 3.92%
  • Veröffentlicht 08.12.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

  • EPSS 0.36%
  • Veröffentlicht 08.12.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article information of their customer tickets...

Exploit
  • EPSS 33.87%
  • Veröffentlicht 08.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell com...

  • EPSS 1.92%
  • Veröffentlicht 07.12.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned...

  • EPSS 17.25%
  • Veröffentlicht 07.12.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construc...

  • EPSS 42.93%
  • Veröffentlicht 07.12.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and would immediately fail if you attempted to continue ...