A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString() is called by the function MQ…
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to…
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
Cryptocat before 2.0.22 has Remote Denial of Service via username
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
Insecure temporary file vulnerability in Redis before 2.6 related to /tmp/redis-%p.vm.
Insecure temporary file vulnerability in Redis 2.6 related to /tmp/redis.ds.
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
evince is missing a check on number of pages which can lead to a segmentation fault
php-symfony2-Validator has loss of information during serialization
Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packe…
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Tro…
Mumble: murmur-server has DoS due to malformed client query
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr a…
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is star…
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
paxtest handles temporary files insecurely
qtparted has insecure library loading which may allow arbitrary code execution
mailscanner can allow local users to prevent virus signatures from being updated
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
Snoopy before 2.0.0 has a security hole in exec cURL
Nessus versions 8.6.0 and earlier were found to contain a Denial of Service vulnerability due to improper validation of specific imported scan types.…
A vulnerability in version 0.90 of the Open Floodlight SDN controller software could result in a denial of service attack and crashing of the control…
A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to…
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it p…