Debian

Debian Linux

9946 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 93.87%
  • Veröffentlicht 16.10.2014 00:55:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

  • EPSS 4.67%
  • Veröffentlicht 16.10.2014 00:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.

  • EPSS 0.5%
  • Veröffentlicht 15.10.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.

  • EPSS 94.02%
  • Veröffentlicht 15.10.2014 00:55:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

  • EPSS 0.07%
  • Veröffentlicht 10.10.2014 01:55:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Libgcrypt before 1.5.4, as used in GnuPG and other products, does not properly perform ciphertext normalization and ciphertext randomization, which makes it easier for physically proximate attackers to conduct key-extraction attacks by leveraging the...

Exploit
  • EPSS 2.82%
  • Veröffentlicht 07.10.2014 14:55:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file.

  • EPSS 34.58%
  • Veröffentlicht 06.10.2014 14:55:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The rfbProcessClientNormalMessage function in libvncserver/rfbserver.c in LibVNCServer 0.9.9 and earlier allows remote attackers to cause a denial of service (divide-by-zero error and server crash) via a zero value in the scaling factor in a (1) Palm...

  • EPSS 0.73%
  • Veröffentlicht 02.10.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.

  • EPSS 1.03%
  • Veröffentlicht 02.10.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which allows local HVM users to cause a denial of service (guest crash) or gain guest kernel mode privileges ...

  • EPSS 6.61%
  • Veröffentlicht 30.09.2014 16:55:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which...