Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 10.77%
  • Veröffentlicht 09.11.2015 03:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mis...

  • EPSS 4.58%
  • Veröffentlicht 09.11.2015 03:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that...

  • EPSS 0.47%
  • Veröffentlicht 06.11.2015 21:59:09
  • Zuletzt bearbeitet 06.05.2026 22:30:45

rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowledgement (ACK) packet, which allows remote attackers to obtain sensitive information by (1) conductin...

  • EPSS 4.25%
  • Veröffentlicht 06.11.2015 21:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_...

  • EPSS 32.05%
  • Veröffentlicht 06.11.2015 18:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (infinite loop) via empty bzip2 data in a ZIP archive.

  • EPSS 33.92%
  • Veröffentlicht 06.11.2015 18:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Info-ZIP UnZip 6.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) or possibly execute arbitrary code via a crafted password-protected ZIP archive, possibly related to an Extra-Field size value...

  • EPSS 1.45%
  • Veröffentlicht 02.11.2015 19:59:16
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the se...

Exploit
  • EPSS 3.23%
  • Veröffentlicht 02.11.2015 19:59:14
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversiz...

  • EPSS 2.05%
  • Veröffentlicht 02.11.2015 19:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a lon...

  • EPSS 6.57%
  • Veröffentlicht 26.10.2015 14:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple stack-based buffer overflows in json parsing in PostgreSQL before 9.3.x before 9.3.10 and 9.4.x before 9.4.5 allow attackers to cause a denial of service (server crash) via unspecified vectors, which are not properly handled in (1) json or (...