Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.41%
  • Veröffentlicht 15.01.2014 16:08:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.33 and earlier and 5.6.13 and earlier allows remote authenticated users to affect availability via unknown vectors related to Partition.

  • EPSS 0.04%
  • Veröffentlicht 07.01.2014 18:55:06
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.

  • EPSS 10.97%
  • Veröffentlicht 23.12.2013 22:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.

  • EPSS 0.25%
  • Veröffentlicht 23.12.2013 22:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to ...

  • EPSS 1.47%
  • Veröffentlicht 09.12.2013 16:36:49
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have uns...

  • EPSS 1.15%
  • Veröffentlicht 07.12.2013 21:55:09
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The atrac3_decode_init function in libavcodec/atrac3.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via ATRAC3 data with the joint stereo coding mode set and fewer than two channels.

  • EPSS 0.32%
  • Veröffentlicht 07.12.2013 20:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.

  • EPSS 17.3%
  • Veröffentlicht 28.11.2013 04:37:39
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted inte...

  • EPSS 9.52%
  • Veröffentlicht 20.11.2013 14:12:30
  • Zuletzt bearbeitet 29.04.2026 01:13:23

lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple...

  • EPSS 6.82%
  • Veröffentlicht 20.11.2013 14:12:30
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.