Debian

Debian Linux

9979 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 12.10.2005 13:04:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a m...

  • EPSS 0.07%
  • Veröffentlicht 05.10.2005 19:02:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.

  • EPSS 0.08%
  • Veröffentlicht 30.09.2005 10:05:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just per...

Exploit
  • EPSS 9.61%
  • Veröffentlicht 28.09.2005 21:03:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE...

  • EPSS 0.09%
  • Veröffentlicht 26.09.2005 19:03:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer ref...

  • EPSS 15.08%
  • Veröffentlicht 06.09.2005 23:03:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass inten...

  • EPSS 0.06%
  • Veröffentlicht 30.08.2005 11:45:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.

  • EPSS 5.31%
  • Veröffentlicht 23.08.2005 04:00:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointe...

  • EPSS 0.09%
  • Veröffentlicht 16.08.2005 04:00:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.

  • EPSS 1.33%
  • Veröffentlicht 15.08.2005 04:00:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function...