Debian

Debian Linux

9947 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 01.06.2016 22:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.

  • EPSS 0.06%
  • Veröffentlicht 01.06.2016 22:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA comma...

  • EPSS 0.07%
  • Veröffentlicht 01.06.2016 22:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.

  • EPSS 1.44%
  • Veröffentlicht 01.06.2016 22:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username st...

  • EPSS 0.4%
  • Veröffentlicht 01.06.2016 22:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random...

  • EPSS 0.6%
  • Veröffentlicht 01.06.2016 22:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops.c in gdk-pixbuf before 2.33.1 allow remote attackers to cause a denial of service (application crash...

  • EPSS 2.52%
  • Veröffentlicht 01.06.2016 20:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

  • EPSS 2.83%
  • Veröffentlicht 26.05.2016 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

  • EPSS 0.09%
  • Veröffentlicht 25.05.2016 15:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).

  • EPSS 0.09%
  • Veröffentlicht 23.05.2016 19:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CV...