Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 6.69%
  • Veröffentlicht 24.08.2015 14:59:10
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.

  • EPSS 1.09%
  • Veröffentlicht 24.08.2015 14:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely la...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 20.08.2015 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parame...

  • EPSS 4.75%
  • Veröffentlicht 16.08.2015 01:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...

  • EPSS 2.05%
  • Veröffentlicht 14.08.2015 18:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The xmlreader in libxml allows remote attackers to cause a denial of service (memory consumption) via crafted XML data, related to an XML Entity Expansion (XEE) attack.

  • EPSS 13.17%
  • Veröffentlicht 12.08.2015 14:59:24
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.

Exploit
  • EPSS 4.27%
  • Veröffentlicht 11.08.2015 14:59:15
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving multiple whitespace characters before an empty href, which triggers a large memory allocation.

Exploit
  • EPSS 4.41%
  • Veröffentlicht 11.08.2015 14:59:14
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Heap-based buffer overflow in the ParseValue function in lexer.c in tidy before 4.9.31 allows remote attackers to cause a denial of service (crash) via vectors involving a command character in an href.

  • EPSS 3.04%
  • Veröffentlicht 06.08.2015 01:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data structure during an unhash operation, which allows local users to gain privileges or cause a denial of service (use-after-free and sy...

  • EPSS 0.05%
  • Veröffentlicht 05.08.2015 18:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted...