Debian

Debian Linux

9950 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Veröffentlicht 24.02.2017 04:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). These might lead to invalid read and write operations, controlled by an attacker.

  • EPSS 0.4%
  • Veröffentlicht 24.02.2017 04:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions that wrap memory allocation.

  • EPSS 0.44%
  • Veröffentlicht 24.02.2017 04:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid read and write operations, controlled by an attacker.

  • EPSS 0.35%
  • Veröffentlicht 24.02.2017 04:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to invalid read and write operations, controlled by an attacker.

  • EPSS 1.19%
  • Veröffentlicht 22.02.2017 23:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Discovery messages. The root cause was relying on BUFSIZ to be compatible with a message size; however, BU...

  • EPSS 0.14%
  • Veröffentlicht 22.02.2017 19:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.

  • EPSS 1.89%
  • Veröffentlicht 22.02.2017 16:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.

  • EPSS 20.04%
  • Veröffentlicht 18.02.2017 21:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double...

  • EPSS 0.42%
  • Veröffentlicht 17.02.2017 07:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

In Wireshark 2.2.4 and earlier, a crafted or malformed STANAG 4607 capture file will cause an infinite loop and memory exhaustion. If the packet size field in a packet header is null, the offset to read from will not advance, causing continuous attem...

  • EPSS 18.26%
  • Veröffentlicht 17.02.2017 07:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. The denial of service is easily achievable as a consequence of backportin...