Debian

Debian Linux

9142 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 05.11.2013 21:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key.

  • EPSS 0.31%
  • Veröffentlicht 02.11.2013 18:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.

Exploit
  • EPSS 3.7%
  • Veröffentlicht 28.10.2013 22:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buf...

  • EPSS 0.11%
  • Veröffentlicht 28.10.2013 22:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration f...

  • EPSS 6.66%
  • Veröffentlicht 17.10.2013 23:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.

Exploit
  • EPSS 1.33%
  • Veröffentlicht 17.10.2013 00:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly ...

  • EPSS 2.71%
  • Veröffentlicht 16.10.2013 20:55:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspeci...

  • EPSS 0.26%
  • Veröffentlicht 16.10.2013 17:55:05
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.

  • EPSS 0.47%
  • Veröffentlicht 16.10.2013 15:55:34
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.

  • EPSS 0.04%
  • Veröffentlicht 03.10.2013 21:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec proce...