Debian

Debian Linux

9140 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 15.24%
  • Veröffentlicht 17.04.2009 00:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

  • EPSS 3.36%
  • Veröffentlicht 08.04.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

  • EPSS 0.07%
  • Veröffentlicht 06.04.2009 14:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode e...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 31.03.2009 18:24:45
  • Zuletzt bearbeitet 09.04.2025 00:30:58

nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.

Exploit
  • EPSS 0.08%
  • Veröffentlicht 30.03.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket ...

  • EPSS 10.02%
  • Veröffentlicht 27.03.2009 16:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid ...

Warnung Exploit
  • EPSS 93.03%
  • Veröffentlicht 26.03.2009 14:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

  • EPSS 0.04%
  • Veröffentlicht 25.03.2009 23:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.

  • EPSS 0.8%
  • Veröffentlicht 25.03.2009 01:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash o...

  • EPSS 0.06%
  • Veröffentlicht 06.03.2009 11:30:02
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass...