Debian

Debian 13 (trixie)

13593 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 03.03.2015 11:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain pri...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 02.03.2015 11:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering u...

  • EPSS 0.06%
  • Veröffentlicht 02.03.2015 11:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) ...

  • EPSS 2.45%
  • Veröffentlicht 02.03.2015 11:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass in...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.03.2015 11:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 09.01.2015 21:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the ...

  • EPSS 0.13%
  • Veröffentlicht 09.01.2015 21:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel...

  • EPSS 0.11%
  • Veröffentlicht 09.01.2015 21:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that...

  • EPSS 2.95%
  • Veröffentlicht 02.01.2015 21:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of an amount of memory, which allows remote attackers t...

  • EPSS 0.08%
  • Veröffentlicht 26.12.2014 00:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The rock_continue function in fs/isofs/rock.c in the Linux kernel through 3.18.1 does not restrict the number of Rock Ridge continuation entries, which allows local users to cause a denial of service (infinite loop, and system crash or hang) via a cr...