Debian

Debian 7 (wheezy)

306 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.1%
  • Veröffentlicht 02.03.2015 11:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering u...

  • EPSS 0.06%
  • Veröffentlicht 02.03.2015 11:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) ...

  • EPSS 2.45%
  • Veröffentlicht 02.03.2015 11:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass in...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 02.03.2015 11:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 09.01.2015 21:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the ...

  • EPSS 0.13%
  • Veröffentlicht 09.01.2015 21:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel...

  • EPSS 0.11%
  • Veröffentlicht 09.01.2015 21:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that...

  • EPSS 0.06%
  • Veröffentlicht 26.12.2014 00:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread Local Storage (TLS) descriptors are loaded before proceeding with other steps, which makes it easier for local users to bypass the...

  • EPSS 0.06%
  • Veröffentlicht 17.12.2014 11:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mec...

  • EPSS 0.04%
  • Veröffentlicht 30.11.2014 01:59:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel through 3.17.4 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to cause a denial of service (panic) via a mo...