Debian

Debian Linux

9947 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.71%
  • Veröffentlicht 12.01.2016 20:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.

  • EPSS 0.74%
  • Veröffentlicht 12.01.2016 20:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.

  • EPSS 5.57%
  • Veröffentlicht 12.01.2016 19:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.

  • EPSS 21.06%
  • Veröffentlicht 08.01.2016 21:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.

  • EPSS 1.75%
  • Veröffentlicht 29.12.2015 22:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during creation of machine accounts, wh...

  • EPSS 43.3%
  • Veröffentlicht 29.12.2015 22:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The LDAP server in the AD domain controller in Samba 4.x before 4.1.22 does not check return values to ensure successful ASN.1 memory allocation, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) via cra...

  • EPSS 9.14%
  • Veröffentlicht 29.12.2015 22:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not verify that the DIRECTORY_LIST access right has been granted, which allows remote att...

  • EPSS 3.65%
  • Veröffentlicht 29.12.2015 22:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in-the-middle attackers to conduct encrypted-to-unencrypted downgrade attacks by modifying the client-s...

Exploit
  • EPSS 17.33%
  • Veröffentlicht 29.12.2015 22:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

vfs.c in smbd in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, when share names with certain substring relationships exist, allows remote attackers to bypass intended file-access restrictions via a symlink that points o...

  • EPSS 20.71%
  • Veröffentlicht 17.12.2015 19:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.