Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 04.11.2016 10:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

  • EPSS 43.01%
  • Veröffentlicht 02.11.2016 17:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive...

  • EPSS 0.85%
  • Veröffentlicht 25.10.2016 14:30:54
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Unspecified vulnerability in Oracle MySQL 5.5.52 and earlier, 5.6.33 and earlier, and 5.7.15 and earlier allows remote administrators to affect confidentiality via vectors related to Server: Security: Encryption.

  • EPSS 4.79%
  • Veröffentlicht 10.10.2016 11:00:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

  • EPSS 0.24%
  • Veröffentlicht 07.10.2016 14:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The put_no_rnd_pixels8_xy2_mmx function in x86/rnd_template.c in libav 11.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted MP3 file.

  • EPSS 0.14%
  • Veröffentlicht 05.10.2016 16:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to ...

  • EPSS 0.14%
  • Veröffentlicht 05.10.2016 16:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU...

  • EPSS 5.18%
  • Veröffentlicht 05.10.2016 16:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.

  • EPSS 1.28%
  • Veröffentlicht 05.10.2016 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.

  • EPSS 5.49%
  • Veröffentlicht 03.10.2016 18:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.