Debian

Debian Linux

9140 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 11.08.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...

  • EPSS 0.43%
  • Veröffentlicht 06.08.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop a...

Exploit
  • EPSS 10.74%
  • Veröffentlicht 05.08.2009 19:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

  • EPSS 25.35%
  • Veröffentlicht 31.07.2009 19:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of a...

Medienbericht
  • EPSS 1.69%
  • Veröffentlicht 30.07.2009 19:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...

  • EPSS 0.06%
  • Veröffentlicht 16.07.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to l...

Exploit
  • EPSS 20.93%
  • Veröffentlicht 10.07.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).

  • EPSS 21.52%
  • Veröffentlicht 05.07.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which al...

  • EPSS 0.06%
  • Veröffentlicht 01.07.2009 13:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang)...

Exploit
  • EPSS 5.39%
  • Veröffentlicht 25.06.2009 01:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vecto...