Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.22%
  • Veröffentlicht 19.11.2013 04:50:56
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of s...

  • EPSS 13.22%
  • Veröffentlicht 18.11.2013 05:23:57
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013.

  • EPSS 7.67%
  • Veröffentlicht 18.11.2013 03:55:05
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon ...

Exploit
  • EPSS 1.48%
  • Veröffentlicht 13.11.2013 15:55:04
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the x-webkit-speech attribute in a text INPUT element.

  • EPSS 6.9%
  • Veröffentlicht 13.11.2013 15:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file an...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 08.11.2013 04:47:22
  • Zuletzt bearbeitet 29.04.2026 01:13:23

lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.

  • EPSS 0.28%
  • Veröffentlicht 05.11.2013 21:55:12
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

  • EPSS 0.15%
  • Veröffentlicht 05.11.2013 21:55:08
  • Zuletzt bearbeitet 29.04.2026 01:13:23

OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key.

  • EPSS 0.31%
  • Veröffentlicht 02.11.2013 18:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.

Exploit
  • EPSS 3.7%
  • Veröffentlicht 28.10.2013 22:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buf...