Vulnerability index

Browse CVEs

90 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2017-16854 In Open Ticket Request System (OTRS) through 3.3.20, 4 through 4.0.26, 5 through 5.0.24, and 6 through 6.0.1, an attacker who is logged in as a custo… Debian Linux after 6.0.1 Fix from $1,6002017-12-08 HIGH 7.5 CVE-2017-8810 MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides different error messages for fai… Debian Linux after 1.27.3 Fix from $1,9502017-11-15 MEDIUM 6.5 CVE-2017-16353EPSS 14% GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil… Debian Linux No fix yet Fix from $1,6002017-11-01 HIGH 7.5 CVE-2017-15576 Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles Time Entry rendering in activity views, which allows remote attackers to obtain sensitive info… Debian Linux after 3.2.5 Fix from $1,9502017-10-18 HIGH 7.5 CVE-2017-15577 Redmine before 3.2.6 and 3.3.x before 3.3.3 mishandles the rendering of wiki links, which allows remote attackers to obtain sensitive information. Debian Linux after 3.2.5 Fix from $1,9502017-10-18 MEDIUM 5.9 CVE-2017-12872 The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote att… Debian Linux after 1.14.11 Fix from $1,6002017-09-01 HIGH 7.5 CVE-2017-0379 Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, rela… Debian Linux after 1.8.0 Fix from $1,9502017-08-29 HIGH 7.5 CVE-2017-9993EPSS 16% FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filenam… Debian Linux 2.8.12 / 3.1.9+ Fix from $1,9502017-06-28 MEDIUM 5.5 CVE-2017-9868 In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic infor… Debian Linux after 1.4.12 Fix from $1,6002017-06-25 HIGH 7.8 CVE-2017-4966 An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb… Debian Linux Mitigation only Fix from $1,9502017-06-13 MEDIUM 5.5 CVE-2013-5653 The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted p… Debian Linux Patch available Fix from $1,6002017-03-07 HIGH 7.5 CVE-2016-10002EPSS 7% Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, an… Debian Linux Patch available Fix from $1,9502017-01-27 MEDIUM 5.3 CVE-2016-6313 The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 mak… Debian Linux after 1.5.3 Fix from $1,6002016-12-13 MEDIUM 6.0 CVE-2016-9103 The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory … Debian Linux after 2.7.1 Fix from $1,6002016-12-09 MEDIUM 6.5 CVE-2016-1698 The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not val… Debian Linux after 51.0.2704.63 Fix from $1,6002016-06-05 MEDIUM 6.5 CVE-2016-1687 The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers… Debian Linux after 50.0.2661.102 Fix from $1,6002016-06-05 HIGH 7.5 CVE-2016-2849 Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which migh… Debian Linux Mitigation only Fix from $1,9502016-05-13 HIGH 7.5 CVE-2016-2055EPSS 18% xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration director… Debian Linux Patch available Fix from $1,9502016-04-13 MEDIUM 5.3 CVE-2016-3170 The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensi… Debian Linux Patch available Fix from $1,6002016-04-12 MEDIUM 5.3 CVE-2015-8537 app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive info… Debian Linux after 2.6.8 Fix from $1,6002016-04-12 HIGH 8.1 CVE-2016-1526 The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before… Debian Linux after 38.5.1 Fix from $1,9502016-02-13 MEDIUM 5.3 CVE-2015-5299EPSS 14% The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before… Debian Linux 4.1.22 / 4.2.7+ Fix from $1,6002015-12-29 MEDIUM 5.0 CVE-2015-7762 rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowl… Debian Linux after 1.6.14.1 Fix from $1,6002015-11-06 MEDIUM 5.0 CVE-2015-1165 RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket… Debian Linux Mitigation only Fix from $1,6002015-03-09 MEDIUM 5.0 CVE-2014-1829 Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected requ… Debian Linux after 2.2.1 Fix from $1,6002014-10-15 MEDIUM 5.0 CVE-2012-2387 devotee 0.1 patch 2 uses a 32-bit seed for generating 48-bit random numbers, which makes it easier for remote attackers to obtain the secret monikers… Devotee Mitigation only Fix from $1,6002012-08-20 MEDIUM 5.0 CVE-2011-4360 MediaWiki before 1.17.1 allows remote attackers to obtain the page titles of all restricted pages via a series of requests involving the (1) curid or… Debian Linux 1.17.1+ Fix from $1,6002012-01-08 MEDIUM 5.0 CVE-2009-1341 Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-depend… Libdbd Pg Perl after 1.4.9 Fix from $1,6002009-04-30 HIGH 7.5 CVE-2008-4359 lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, w… Debian Linux 1.4.20+ Fix from $1,9502008-10-03 HIGH 7.5 CVE-2008-4360 mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filenam… Debian Linux 1.4.20+ Fix from $1,9502008-10-03