Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.08%
  • Veröffentlicht 06.07.2017 16:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows remote attackers to cause a denial of service (segmentation fault and server crash) by leveraging failure to ensure that all initi...

  • EPSS 1.45%
  • Veröffentlicht 05.07.2017 15:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAML deserialization in an unsafe manner, which would lead to remote code...

  • EPSS 0.83%
  • Veröffentlicht 04.07.2017 20:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel through 4.11.8 allows attackers to cause a denial of service (memory consumption) by triggering object-initialization failures.

Exploit
  • EPSS 10.05%
  • Veröffentlicht 29.06.2017 08:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Use-after-free in the XML-LibXML module through 2.0129 for Perl allows remote attackers to execute arbitrary code by controlling the arguments to a replaceChild call.

Exploit
  • EPSS 0.63%
  • Veröffentlicht 28.06.2017 06:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

The readEncUInt30 function in util/read.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack against parser.c.

Exploit
  • EPSS 0.63%
  • Veröffentlicht 28.06.2017 06:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

util/outputtxt.c in libming 0.4.8 mishandles memory allocation. A crafted input will lead to a remote denial of service (NULL pointer dereference) attack.

  • EPSS 0.74%
  • Veröffentlicht 28.06.2017 06:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 allows remote attackers to cause a denial of service (application c...

  • EPSS 56.17%
  • Veröffentlicht 28.06.2017 06:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filename extensions and demuxer names, which allows attackers to read arbitrary files via crafted playlist d...

  • EPSS 0.42%
  • Veröffentlicht 28.06.2017 06:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pix_fmt is set, which allows remote attackers to cause a denial of service (heap-based buffer overflow ...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 26.06.2017 12:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different damages. For example, a crafted TIFF document can lead to an out-of-bounds read in TIFFCleanup, an i...