Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 17.29%
  • Veröffentlicht 07.12.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult...

  • EPSS 0.19%
  • Veröffentlicht 07.12.2017 02:29:13
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error and QEMU process crash) by unsetting vring alignment while updating Virtio rings.

  • EPSS 9.18%
  • Veröffentlicht 06.12.2017 15:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm. The parser would unconditionally dereference NULL pointers in that case, leading...

  • EPSS 1.56%
  • Veröffentlicht 06.12.2017 03:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The recv_files function in receiver.c in the daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, proceeds with certain file metadata updates before checking for a filename in the daemon_filter_list data structure, which allows remote atta...

  • EPSS 1.16%
  • Veröffentlicht 06.12.2017 03:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The daemon in rsync 3.1.2, and 3.1.3-development before 2017-12-03, does not check for fnamecmp filenames in the daemon_filter_list data structure (in the recv_files function in receiver.c) and also does not apply the sanitize_paths protection mechan...

  • EPSS 1.24%
  • Veröffentlicht 06.12.2017 00:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

OpenAFS 1.x before 1.6.22 does not properly validate Rx ack packets, which allows remote attackers to cause a denial of service (system crash or application crash) via crafted fields, as demonstrated by an integer underflow and assertion failure for ...

  • EPSS 0.02%
  • Veröffentlicht 05.12.2017 23:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application.

  • EPSS 3.04%
  • Veröffentlicht 05.12.2017 16:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.

  • EPSS 0.55%
  • Veröffentlicht 03.12.2017 07:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send ...

  • EPSS 0.82%
  • Veröffentlicht 03.12.2017 07:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, remote attackers can cause a denial of service (NULL pointer dereference and application crash) against directory aut...