Debian

Debian Linux

9947 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.11%
  • Veröffentlicht 16.04.2015 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

chrony before 1.31.1 does not initialize the last "next" pointer when saving unacknowledged replies to command requests, which allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and daemon crash) or poss...

  • EPSS 2.61%
  • Veröffentlicht 16.04.2015 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute arbitrary code by configuring the (1) NTP or (2) cmdmon access with a subnet size that is indivisibl...

  • EPSS 1.88%
  • Veröffentlicht 16.04.2015 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which triggers a buffer overflow.

  • EPSS 7.8%
  • Veröffentlicht 14.04.2015 18:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecified impact via unknown vectors that trigger an error condition, related to binding octets to columns.

Exploit
  • EPSS 3.8%
  • Veröffentlicht 13.04.2015 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.

  • EPSS 9.35%
  • Veröffentlicht 10.04.2015 15:00:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.

  • EPSS 5.45%
  • Veröffentlicht 08.04.2015 18:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.

  • EPSS 0.12%
  • Veröffentlicht 01.04.2015 14:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O ...

  • EPSS 0.14%
  • Veröffentlicht 01.04.2015 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.

  • EPSS 32.29%
  • Veröffentlicht 01.04.2015 02:00:35
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial ...