Debian

Debian Linux

9142 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.38%
  • Published 04.11.2014 16:55:06
  • Last modified 12.04.2025 10:46:40

parser.c in libxml2 before 2.9.2 does not properly prevent entity expansion even when entity substitution has been disabled, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted XML document containing...

  • EPSS 0.09%
  • Published 01.11.2014 23:55:09
  • Last modified 12.04.2025 10:46:40

The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution.

  • EPSS 1.27%
  • Published 29.10.2014 10:55:04
  • Last modified 12.04.2025 10:46:40

The (1) bundled GnuTLS SSL/TLS plugin and the (2) bundled OpenSSL SSL/TLS plugin in libpurple in Pidgin before 2.10.10 do not properly consider the Basic Constraints extension during verification of X.509 certificates from SSL servers, which allows m...

Exploit
  • EPSS 0.45%
  • Published 20.10.2014 17:55:06
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in data_sources.php in Cacti 0.8.8b allows remote authenticated users with console access to inject arbitrary web script or HTML via the name_cache parameter in a ds_edit action.

Exploit
  • EPSS 0.35%
  • Published 20.10.2014 17:55:06
  • Last modified 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote authenticated users with console access to inject arbitrary web script or HTML via a (1) Graph Tree Title in a delete or (2) edit action; (3) CDEF Name, (4) Data Input M...

  • EPSS 2.81%
  • Published 20.10.2014 17:55:05
  • Last modified 12.04.2025 10:46:40

Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors rela...

Exploit
  • EPSS 94.37%
  • Published 16.10.2014 00:55:06
  • Last modified 12.04.2025 10:46:40

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

  • EPSS 4.67%
  • Published 16.10.2014 00:55:05
  • Last modified 12.04.2025 10:46:40

wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.

  • EPSS 0.5%
  • Published 15.10.2014 14:55:05
  • Last modified 12.04.2025 10:46:40

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.

  • EPSS 94.02%
  • Published 15.10.2014 00:55:02
  • Last modified 12.04.2025 10:46:40

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.