Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.33%
  • Veröffentlicht 16.02.2016 02:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted para...

Warnung Exploit
  • EPSS 92.71%
  • Veröffentlicht 16.02.2016 02:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unre...

  • EPSS 35.5%
  • Veröffentlicht 15.02.2016 19:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

  • EPSS 11.58%
  • Veröffentlicht 15.02.2016 19:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response relate...

  • EPSS 81.25%
  • Veröffentlicht 15.02.2016 19:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

  • EPSS 1.24%
  • Veröffentlicht 14.02.2016 02:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase parameter is associated with a chrome-devtools-frontend.appspot.com URL, which allows remote attackers to ...

  • EPSS 0.64%
  • Veröffentlicht 14.02.2016 02:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (out-of-bounds read) via a craft...

  • EPSS 0.64%
  • Veröffentlicht 14.02.2016 02:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation target is on the most-visited or suggestions list, which allows remote attackers to bypass intended restrictions via unspecified vec...

  • EPSS 1.42%
  • Veröffentlicht 14.02.2016 02:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.0.2564.109, allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via c...

  • EPSS 1.53%
  • Veröffentlicht 14.02.2016 02:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-detach operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web s...