Debian

Debian Linux

9944 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.78%
  • Veröffentlicht 29.04.2011 22:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

acl.c in Tinyproxy before 1.8.3, when an Allow configuration setting specifies a CIDR block, permits TCP connections from all IP addresses, which makes it easier for remote attackers to hide the origin of web traffic by leveraging the open HTTP proxy...

  • EPSS 73.5%
  • Veröffentlicht 08.04.2011 15:17:27
  • Zuletzt bearbeitet 11.04.2025 00:51:21

dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstra...

  • EPSS 0.96%
  • Veröffentlicht 29.03.2011 18:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The configuration merger in itk.c in the Steinar H. Gunderson mpm-itk Multi-Processing Module 2.2.11-01 and 2.2.11-02 for the Apache HTTP Server does not properly handle certain configuration sections that specify NiceValue but not AssignUserID, whic...

  • EPSS 3.07%
  • Veröffentlicht 25.03.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain program...

Exploit
  • EPSS 1.37%
  • Veröffentlicht 25.03.2011 19:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

  • EPSS 1.45%
  • Veröffentlicht 25.03.2011 19:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

Exploit
  • EPSS 45.28%
  • Veröffentlicht 02.03.2011 20:00:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions...

Exploit
  • EPSS 68.83%
  • Veröffentlicht 22.02.2011 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to port 5353. NOTE: this vulnerability exists because of an incorrect f...

Exploit
  • EPSS 2.24%
  • Veröffentlicht 10.02.2011 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."

Exploit
  • EPSS 1.85%
  • Veröffentlicht 10.02.2011 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Google Chrome before 9.0.597.94 does not properly handle anonymous blocks, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."