Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.95%
  • Veröffentlicht 11.12.2017 02:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.

  • EPSS 0.95%
  • Veröffentlicht 11.12.2017 02:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.

Exploit
  • EPSS 0.98%
  • Veröffentlicht 11.12.2017 02:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage.

  • EPSS 3.92%
  • Veröffentlicht 08.12.2017 19:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly remote code execution.

  • EPSS 0.36%
  • Veröffentlicht 08.12.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a customer can use the ticket search form to disclose internal article information of their customer tickets...

Exploit
  • EPSS 33.87%
  • Veröffentlicht 08.12.2017 15:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell com...

  • EPSS 1.92%
  • Veröffentlicht 07.12.2017 19:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and ConfigResponse messages. This info leak is a result of uninitialized stack variables that may be returned...

  • EPSS 17.25%
  • Veröffentlicht 07.12.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use of Mercurial prevents construc...

  • EPSS 42.93%
  • Veröffentlicht 07.12.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and would immediately fail if you attempted to continue ...

  • EPSS 15.51%
  • Veröffentlicht 07.12.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult...