Debian

Debian Linux

9922 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.64%
  • Veröffentlicht 04.08.2017 09:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. Th...

  • EPSS 6.24%
  • Veröffentlicht 02.08.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

qemu-nbd in QEMU (aka Quick Emulator) does not ignore SIGPIPE, which allows remote attackers to cause a denial of service (daemon crash) by disconnecting during a server-to-client reply attempt.

  • EPSS 0.09%
  • Veröffentlicht 02.08.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Stack-based buffer overflow in hw/usb/redirect.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (QEMU process crash) via vectors related to logging debug messages.

  • EPSS 0.04%
  • Veröffentlicht 02.08.2017 19:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The address_space_write_continue function in exec.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds access and guest instance crash) by leveraging use of qemu_map_ram_ptr to access guest...

Exploit
  • EPSS 2.84%
  • Veröffentlicht 31.07.2017 13:29:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file.

Exploit
  • EPSS 3.88%
  • Veröffentlicht 31.07.2017 13:29:01
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.

Exploit
  • EPSS 4.54%
  • Veröffentlicht 31.07.2017 13:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.

  • EPSS 0.22%
  • Veröffentlicht 29.07.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

  • EPSS 0.32%
  • Veröffentlicht 29.07.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, which allows attackers to cause a denial of service via a crafted file.

  • EPSS 0.34%
  • Veröffentlicht 28.07.2017 05:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PostScript document,...