Debian

Debian Linux

9947 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.68%
  • Veröffentlicht 13.03.2015 14:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.

  • EPSS 0.24%
  • Veröffentlicht 12.03.2015 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly...

  • EPSS 0.08%
  • Veröffentlicht 12.03.2015 14:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors.

  • EPSS 0.39%
  • Veröffentlicht 09.03.2015 14:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.

  • EPSS 0.88%
  • Veröffentlicht 09.03.2015 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.

  • EPSS 3.57%
  • Veröffentlicht 08.03.2015 02:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length...

  • EPSS 0.41%
  • Veröffentlicht 08.03.2015 02:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via...

  • EPSS 0.34%
  • Veröffentlicht 08.03.2015 02:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out-of-bounds read and applicatio...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 02.03.2015 11:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering u...

  • EPSS 0.05%
  • Veröffentlicht 02.03.2015 11:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) ...