Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.3%
  • Veröffentlicht 20.11.2017 22:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to tr...

  • EPSS 1.14%
  • Veröffentlicht 20.11.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resu...

  • EPSS 1.06%
  • Veröffentlicht 20.11.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

By exploiting the way Apache OpenOffice before 4.1.4 renders embedded objects, an attacker could craft a document that allows reading in a file from the user's filesystem. Information could be retrieved by the attacker by, e.g., using hidden sections...

  • EPSS 0.84%
  • Veröffentlicht 20.11.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to craft malicious documents that cause denial of service (memory corruption and application crash) potentially resulting in arbitrary c...

  • EPSS 0.43%
  • Veröffentlicht 20.11.2017 18:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An array index error in the fig2dev program in Xfig 3.2.6a allows remote attackers to cause a denial-of-service attack or information disclosure with a maliciously crafted Fig format file, related to a negative font value in dev/gentikz.c, and the re...

Exploit
  • EPSS 3.31%
  • Veröffentlicht 20.11.2017 15:29:00
  • Zuletzt bearbeitet 09.06.2025 16:15:26

In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the termin...

  • EPSS 2.07%
  • Veröffentlicht 17.11.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.

  • EPSS 0.87%
  • Veröffentlicht 17.11.2017 09:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cseq, ttl, port, etc.) all had the potential to overflow, either causing unintended values to be capture...

  • EPSS 3.72%
  • Veröffentlicht 17.11.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

Exploit
  • EPSS 0.47%
  • Veröffentlicht 17.11.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.