Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.83%
  • Veröffentlicht 15.11.2017 08:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater than) characters via the id attribute of a headline.

  • EPSS 0.65%
  • Veröffentlicht 15.11.2017 08:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a rule definition followed by "a lot of junk."

  • EPSS 0.4%
  • Veröffentlicht 15.11.2017 08:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rules.

  • EPSS 71.13%
  • Veröffentlicht 13.11.2017 22:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL ser...

  • EPSS 0.35%
  • Veröffentlicht 13.11.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

Warnung Exploit
  • EPSS 38.27%
  • Veröffentlicht 09.11.2017 14:29:00
  • Zuletzt bearbeitet 22.10.2025 00:16:05

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to...

Exploit
  • EPSS 1.13%
  • Veröffentlicht 09.11.2017 00:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in m...

Exploit
  • EPSS 8.37%
  • Veröffentlicht 07.11.2017 21:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the in...

  • EPSS 1.16%
  • Veröffentlicht 06.11.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which triggers an out-of-bounds read.

  • EPSS 2.94%
  • Veröffentlicht 06.11.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) ...