Vulnerability index

Browse CVEs

27 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.3 CVE-2023-2255 Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external… Debian Linux 7.4.7 / 7.5.3+ Fix from $1,6002023-05-25 MEDIUM 5.5 CVE-2014-2079 X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to … Debian Linux Patch available Fix from $1,6002018-07-16 HIGH 7.8 CVE-2016-9775 The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1u… Debian Linux Mitigation only Fix from $1,9502017-03-23 MEDIUM 5.9 CVE-2016-7142 The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof ce… Debian Linux after 2.0.22 Fix from $1,6002016-09-26 HIGH 7.8 CVE-2016-1238 (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/… Debian Linux 3.4.2+ Fix from $1,9502016-08-02 HIGH 7.8 CVE-2015-5723 Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x b… Debian Linux after 2.4.7 Fix from $1,9502016-06-07 HIGH 7.8 CVE-2015-8325 The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_envi… Debian Linux after 7.2 Fix from $1,9502016-05-01 HIGH 8.1 CVE-2016-3169 The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code tha… Debian Linux Patch available Fix from $1,9502016-04-12 HIGH 8.8 CVE-2016-1235 The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via … Debian Linux after 2.5.6 Fix from $1,9502016-04-11 MEDIUM 6.3 CVE-2016-0763EPSS 11% The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x befo… Debian Linux Mitigation only Fix from $1,6002016-02-25 HIGH 8.8 CVE-2016-1627 The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase param… Debian Linux after 48.0.2564.103 Fix from $1,9502016-02-14 HIGH 8.8 CVE-2016-1623 The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-… Debian Linux after 48.0.2564.103 Fix from $1,9502016-02-14 HIGH 7.8 CVE-2016-1233 An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world… Fuse after 2.9.3-14 Fix from $1,9502016-01-26 MEDIUM 5.0 CVE-2015-1254 core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remot… Debian Linux after 42.0.2311.152 Fix from $1,6002015-05-20 MEDIUM 5.8 CVE-2014-7155 The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which al… Debian Linux after 4.4.0 Fix from $1,6002014-10-02 MEDIUM 6.8 CVE-2014-3160 The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly… Debian Linux Mitigation only Fix from $1,6002014-07-20 HIGH 7.5 CVE-2013-6410 nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended acces… Debian Linux after 3.4 Fix from $1,9502013-12-07 MEDIUM 6.2 CVE-2013-6409 Debian adequate before 0.8.1, when run by root with the --user option, allows local users to hijack the tty and possibly gain privileges via the TIOC… Adequate after 0.8 Fix from $1,6002013-12-07 HIGH 7.6 CVE-2013-4559EPSS 11% lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run a… Debian Linux 1.4.33+ Fix from $1,9502013-11-20 MEDIUM 5.0 CVE-2013-2905 The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which … Debian Linux after 29.0.1547.56 Fix from $1,6002013-08-21 MEDIUM 5.0 CVE-2013-2876 browser/extensions/api/tabs/tabs_api.cc in Google Chrome before 28.0.1500.71 does not properly enforce restrictions on the capture of screenshots by … Debian Linux after 28.0.1500.70 Fix from $1,6002013-07-10 HIGH 7.2 CVE-2004-2768 dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain… Dpkg No fix yet Fix from $1,9502010-06-08 MEDIUM 5.8 CVE-2009-1888 The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, whe… Debian Linux 3.2.13 / 3.3.6+ Fix from $1,6002009-06-25 HIGH 7.2 CVE-2007-3912 checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a ru… Debian Goodies Patch available Fix from $1,9502007-09-10 MEDIUM 5.0 CVE-2007-4739 reprepro 1.3.0 through 2.2.3 does not properly verify signatures when updating repositories, which allows remote attackers to construct and distribut… Reprepro Patch available Fix from $1,6002007-09-06 MEDIUM 6.6 CVE-2006-7098 The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when http… Apache Mitigation only Fix from $1,6002007-03-03 HIGH 7.2 CVE-2004-0793 The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execu… Bsdmainutils Patch available Fix from $1,9502004-10-20