Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.06%
  • Veröffentlicht 17.04.2012 21:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.

  • EPSS 4.46%
  • Veröffentlicht 22.03.2012 16:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly exe...

Exploit
  • EPSS 8.57%
  • Veröffentlicht 01.02.2012 16:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corr...

  • EPSS 3.95%
  • Veröffentlicht 01.02.2012 16:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...

Exploit
  • EPSS 1.44%
  • Veröffentlicht 01.02.2012 16:55:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corru...

  • EPSS 33.85%
  • Veröffentlicht 28.01.2012 04:05:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors i...

Exploit
  • EPSS 1.04%
  • Veröffentlicht 18.01.2012 20:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memor...

  • EPSS 0.18%
  • Veröffentlicht 08.01.2012 11:55:19
  • Zuletzt bearbeitet 29.04.2026 01:13:23

MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an...

  • EPSS 0.61%
  • Veröffentlicht 08.01.2012 11:55:18
  • Zuletzt bearbeitet 29.04.2026 01:13:23

MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or (2) oldid parameter.

  • EPSS 3.19%
  • Veröffentlicht 07.01.2012 11:55:13
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.