Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 05.10.2017 01:29:04
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Linux kernel: heap out-of-bounds in AF_PACKET sockets. This new issue is analogous to previously disclosed CVE-2016-8655. In both cases, a socket option that changes socket state may race with safety checks in packet_set_ring. Previously with PACKET_...

  • EPSS 2.14%
  • Veröffentlicht 05.10.2017 01:29:04
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mercurial prior to version 4.3 is vulnerable to a missing symlink check that can malicious repositories to modify files outside the repository

  • EPSS 5.58%
  • Veröffentlicht 05.10.2017 01:29:04
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Mercurial prior to 4.3 did not adequately sanitize hostnames passed to ssh, leading to possible shell-injection attacks.

Exploit
  • EPSS 2.35%
  • Veröffentlicht 04.10.2017 01:29:03
  • Zuletzt bearbeitet 13.05.2026 00:24:29

ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield an image list with zero frames...

  • EPSS 1.85%
  • Veröffentlicht 04.10.2017 01:29:03
  • Zuletzt bearbeitet 13.05.2026 00:24:29

GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.

  • EPSS 1%
  • Veröffentlicht 04.10.2017 01:29:02
  • Zuletzt bearbeitet 13.05.2026 00:24:29

OpenVPN versions before 2.3.3 and 2.4.x before 2.4.4 are vulnerable to a buffer overflow vulnerability when key-method 1 is used, possibly resulting in code execution.

Warnung Exploit
  • EPSS 94.38%
  • Veröffentlicht 04.10.2017 01:29:02
  • Zuletzt bearbeitet 21.04.2026 17:03:52

When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload ...

Exploit
  • EPSS 49.79%
  • Veröffentlicht 04.10.2017 01:29:02
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

Exploit
  • EPSS 0.38%
  • Veröffentlicht 03.10.2017 01:29:03
  • Zuletzt bearbeitet 13.05.2026 00:24:29

WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database rea...

  • EPSS 92.84%
  • Veröffentlicht 03.10.2017 01:29:02
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.