Debian

Debian Linux

9946 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 5.21%
  • Veröffentlicht 24.11.2014 16:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

  • EPSS 1.76%
  • Veröffentlicht 24.11.2014 15:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The do_mmu_update function in arch/x86/mm.c in Xen 3.2.x through 4.4.x does not properly manage page references, which allows remote domains to cause a denial of service by leveraging control over an HVM guest and a crafted MMU_MACHPHYS_UPDATE.

  • EPSS 79.79%
  • Veröffentlicht 24.11.2014 15:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x-2.1 for Drupal allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted request.

  • EPSS 1.91%
  • Veröffentlicht 24.11.2014 15:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to a server that supports both HTTP and HTTPS sessions.

  • EPSS 0.16%
  • Veröffentlicht 24.11.2014 15:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".

  • EPSS 0.07%
  • Veröffentlicht 19.11.2014 18:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

arch/x86/x86_emulate/x86_emulate.c in Xen 3.2.1 through 4.4.x does not properly check privileges, which allows local HVM guest users to gain privileges or cause a denial of service (crash) via a crafted (1) CALL, (2) JMP, (3) RETF, (4) LCALL, (5) LJM...

  • EPSS 1.42%
  • Veröffentlicht 19.11.2014 18:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The do_mmu_update function in arch/x86/mm.c in Xen 4.x through 4.4.x does not properly restrict updates to only PV page tables, which allows remote PV guests to cause a denial of service (NULL pointer dereference) by leveraging hardware emulation ser...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 18.11.2014 15:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vu...

  • EPSS 3.45%
  • Veröffentlicht 15.11.2014 20:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Off-by-one error in the encodes function in pack.c in Ruby 1.9.3 and earlier, and 2.x through 2.1.2, when using certain format string specifiers, allows context-dependent attackers to cause a denial of service (segmentation fault) via vectors that tr...

  • EPSS 0.37%
  • Veröffentlicht 15.11.2014 20:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to r...