Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.1%
  • Veröffentlicht 02.10.2017 01:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.

  • EPSS 0.29%
  • Veröffentlicht 30.09.2017 01:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.

  • EPSS 0.29%
  • Veröffentlicht 30.09.2017 01:29:02
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.

  • EPSS 6.97%
  • Veröffentlicht 29.09.2017 01:34:50
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Git before 2.10.5, 2.11.x before 2.11.4, 2.12.x before 2.12.5, 2.13.x before 2.13.6, and 2.14.x before 2.14.2 uses unsafe Perl scripts to support subcommands such as cvsserver, which allows attackers to execute arbitrary OS commands via shell metacha...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 29.09.2017 01:34:49
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An Invalid memory address dereference was discovered in Exiv2::StringValueBase::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 29.09.2017 01:34:49
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 29.09.2017 01:34:49
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

  • EPSS 0.05%
  • Veröffentlicht 26.09.2017 01:29:03
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A cryptographic cache-based side channel in the RSA implementation in Botan before 1.10.17, and 1.11.x and 2.x before 2.3.0, allows a local attacker to recover information about RSA secret keys, as demonstrated by CacheD. This occurs because an array...

  • EPSS 1.42%
  • Veröffentlicht 25.09.2017 21:29:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.

  • EPSS 2.04%
  • Veröffentlicht 25.09.2017 17:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Cross-site scripting (XSS) vulnerability in jsoup before 1.8.3.