Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 71.13%
  • Veröffentlicht 13.11.2017 22:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL ser...

  • EPSS 0.35%
  • Veröffentlicht 13.11.2017 20:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.

Warnung Exploit
  • EPSS 37.27%
  • Veröffentlicht 09.11.2017 14:29:00
  • Zuletzt bearbeitet 21.04.2026 18:00:40

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files, as exploited in the wild in November 2017. The attacker must be able to...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 09.11.2017 00:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in m...

Exploit
  • EPSS 8.26%
  • Veröffentlicht 07.11.2017 21:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to supply date strings to leak information from the in...

  • EPSS 1.16%
  • Veröffentlicht 06.11.2017 17:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via a crafted MP4 file, which triggers an out-of-bounds read.

  • EPSS 3.34%
  • Veröffentlicht 06.11.2017 05:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) ...

  • EPSS 0.32%
  • Veröffentlicht 05.11.2017 22:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or po...

Exploit
  • EPSS 7.69%
  • Veröffentlicht 04.11.2017 18:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: T...

  • EPSS 0.09%
  • Veröffentlicht 04.11.2017 01:29:37
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB devic...