Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Debian Linux MEDIUM 5.3
CVE-2023-2255

Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external…

Fix: 7.4.7 / 7.5.3+
Fix from $1,600 2023-05-25
Debian Linux MEDIUM 5.5
CVE-2014-2079

X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to …

Patch available
Fix from $1,600 2018-07-16
Debian Linux HIGH 7.8
CVE-2016-9775

The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1u…

Mitigation only
Fix from $1,950 2017-03-23
Debian Linux MEDIUM 5.9
CVE-2016-7142

The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof ce…

Fix: after 2.0.22
Fix from $1,600 2016-09-26
Debian Linux HIGH 7.8
CVE-2016-1238

(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/…

Fix: 3.4.2+
Fix from $1,950 2016-08-02
Debian Linux HIGH 7.8
CVE-2015-5723

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x b…

Fix: after 2.4.7
Fix from $1,950 2016-06-07
Debian Linux HIGH 7.8
CVE-2015-8325

The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_envi…

Fix: after 7.2
Fix from $1,950 2016-05-01
Debian Linux HIGH 8.1
CVE-2016-3169

The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code tha…

Patch available
Fix from $1,950 2016-04-12
Debian Linux HIGH 8.8
CVE-2016-1235

The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via …

Fix: after 2.5.6
Fix from $1,950 2016-04-11
Debian Linux MEDIUM 6.3
CVE-2016-0763EPSS 11%

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x befo…

Mitigation only
Fix from $1,600 2016-02-25
Debian Linux HIGH 8.8
CVE-2016-1627

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase param…

Fix: after 48.0.2564.103
Fix from $1,950 2016-02-14
Debian Linux HIGH 8.8
CVE-2016-1623

The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-…

Fix: after 48.0.2564.103
Fix from $1,950 2016-02-14
Fuse HIGH 7.8
CVE-2016-1233

An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world…

Fix: after 2.9.3-14
Fix from $1,950 2016-01-26
Debian Linux MEDIUM 5.0
CVE-2015-1254

core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remot…

Fix: after 42.0.2311.152
Fix from $1,600 2015-05-20
Debian Linux MEDIUM 5.8
CVE-2014-7155

The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which al…

Fix: after 4.4.0
Fix from $1,600 2014-10-02
Debian Linux MEDIUM 6.8
CVE-2014-3160

The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly…

Mitigation only
Fix from $1,600 2014-07-20
Debian Linux HIGH 7.5
CVE-2013-6410

nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended acces…

Fix: after 3.4
Fix from $1,950 2013-12-07
Adequate MEDIUM 6.2
CVE-2013-6409

Debian adequate before 0.8.1, when run by root with the --user option, allows local users to hijack the tty and possibly gain privileges via the TIOC…

Fix: after 0.8
Fix from $1,600 2013-12-07
Debian Linux HIGH 7.6
CVE-2013-4559EPSS 11%

lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run a…

Fix: 1.4.33+
Fix from $1,950 2013-11-20
Debian Linux MEDIUM 5.0
CVE-2013-2905

The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which …

Fix: after 29.0.1547.56
Fix from $1,600 2013-08-21
Debian Linux MEDIUM 5.0
CVE-2013-2876

browser/extensions/api/tabs/tabs_api.cc in Google Chrome before 28.0.1500.71 does not properly enforce restrictions on the capture of screenshots by …

Fix: after 28.0.1500.70
Fix from $1,600 2013-07-10
Dpkg HIGH 7.2
CVE-2004-2768

dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain…

No fix yet
Fix from $1,950 2010-06-08
Debian Linux MEDIUM 5.8
CVE-2009-1888

The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, whe…

Fix: 3.2.13 / 3.3.6+
Fix from $1,600 2009-06-25
Debian Goodies HIGH 7.2
CVE-2007-3912

checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a ru…

Patch available
Fix from $1,950 2007-09-10
Reprepro MEDIUM 5.0
CVE-2007-4739

reprepro 1.3.0 through 2.2.3 does not properly verify signatures when updating repositories, which allows remote attackers to construct and distribut…

Patch available
Fix from $1,600 2007-09-06
Apache MEDIUM 6.6
CVE-2006-7098

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when http…

Mitigation only
Fix from $1,600 2007-03-03
Bsdmainutils HIGH 7.2
CVE-2004-0793

The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execu…

Patch available
Fix from $1,950 2004-10-20