Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.56%
  • Veröffentlicht 05.05.2008 16:20:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY argume...

  • EPSS 0.07%
  • Veröffentlicht 02.05.2008 16:05:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.

Exploit
  • EPSS 2.39%
  • Veröffentlicht 18.04.2008 17:05:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when asse...

Exploit
  • EPSS 28.41%
  • Veröffentlicht 10.04.2008 19:05:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.

  • EPSS 0.04%
  • Veröffentlicht 31.03.2008 22:44:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

  • EPSS 3.52%
  • Veröffentlicht 27.03.2008 23:44:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a...

  • EPSS 16.26%
  • Veröffentlicht 19.03.2008 10:44:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer derefe...

  • EPSS 4.9%
  • Veröffentlicht 19.03.2008 10:44:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."

  • EPSS 19.04%
  • Veröffentlicht 17.03.2008 21:44:00
  • Zuletzt bearbeitet 01.05.2025 15:33:00

The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a ...

Exploit
  • EPSS 1.96%
  • Veröffentlicht 25.01.2008 00:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.