Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 07.06.2016 14:06:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation.

  • EPSS 0.13%
  • Veröffentlicht 07.06.2016 14:06:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter...

  • EPSS 1.16%
  • Veröffentlicht 07.06.2016 14:06:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

  • EPSS 0.85%
  • Veröffentlicht 07.06.2016 14:06:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do...

  • EPSS 1%
  • Veröffentlicht 05.06.2016 23:59:33
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.79 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

  • EPSS 1.42%
  • Veröffentlicht 05.06.2016 23:59:32
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted serial...

  • EPSS 1.35%
  • Veröffentlicht 05.06.2016 23:59:31
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Autofill implementation in Google Chrome before 51.0.2704.79 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possi...

  • EPSS 1.72%
  • Veröffentlicht 05.06.2016 23:59:30
  • Zuletzt bearbeitet 12.04.2025 10:46:40

extensions/renderer/runtime_custom_bindings.cc in Google Chrome before 51.0.2704.79 does not consider side effects during creation of an array of extension views, which allows remote attackers to cause a denial of service (use-after-free) or possibly...

  • EPSS 0.58%
  • Veröffentlicht 05.06.2016 23:59:29
  • Zuletzt bearbeitet 12.04.2025 10:46:40

WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl parameter is associated with a chrome-devtools-frontend.ap...

  • EPSS 0.82%
  • Veröffentlicht 05.06.2016 23:59:28
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to load arbitrary modules or obtain sensitive informa...