Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 74.5%
  • Veröffentlicht 25.11.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via vectors involving BDAT commands.

Exploit
  • EPSS 76.03%
  • Veröffentlicht 25.11.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial of service (infinite loop and stack exhaustion) via vectors involving BDAT commands and an improper check for a '.' character sig...

Exploit
  • EPSS 7.16%
  • Veröffentlicht 24.11.2017 10:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted SO_RCVBUF setsockopt system call in conjunction with XFRM...

  • EPSS 0.12%
  • Veröffentlicht 23.11.2017 06:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, which allows local users to cause a denial of service (buffer overflow and application crash) or possib...

  • EPSS 30.23%
  • Veröffentlicht 22.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full re...

  • EPSS 0.77%
  • Veröffentlicht 22.11.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server me...

  • EPSS 1.22%
  • Veröffentlicht 21.11.2017 14:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user...

  • EPSS 2.35%
  • Veröffentlicht 21.11.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieved from the Swauth middleware authentication mechani...

  • EPSS 1.59%
  • Veröffentlicht 21.11.2017 08:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c and libavcodec/vc2enc_dwt.c.

  • EPSS 0.56%
  • Veröffentlicht 20.11.2017 22:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger...