Vulnerability index

Browse CVEs

29 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Debian Linux HIGH 7.8
CVE-2023-26604

systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "sys…

Fix: 246.7+
Fix from $1,950 2023-03-03
Debian Linux HIGH 7.8
CVE-2023-22809EPSS 55%

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VIS…

Fix: 1.9.12 / 13.4+
Fix from $1,950 2023-01-18
Debian Linux HIGH 8.8
CVE-2022-39286

Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code exec…

Fix: 4.11.2+
Fix from $1,950 2022-10-26
Debian Linux HIGH 8.8
CVE-2019-9971

PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tc…

No fix yet
Fix from $1,950 2022-06-07
Debian Linux HIGH 8.8
CVE-2022-21699

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python prog…

Fix: 7.16.3 / 7.31.1+
Fix from $1,950 2022-01-19
Debian Linux MEDIUM 6.5
CVE-2021-43528

Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive ch…

Fix: 91.4.0+
Fix from $1,600 2021-12-08
Debian Linux HIGH 8.8
CVE-2021-32739

Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor…

Fix: 2.11.10 / 2.12.5+
Fix from $1,950 2021-07-15
Shadow HIGH 7.8
CVE-2017-20002

The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local user…

No fix yet
Fix from $1,950 2021-03-17
Debian Linux HIGH 8.8
CVE-2020-29481

An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not r…

Fix: after 4.14.0
Fix from $1,950 2020-12-15
Debian Linux MEDIUM 5.5
CVE-2020-3812

qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and d…

Patch available
Fix from $1,600 2020-05-26
Debian Linux MEDIUM 5.3
CVE-2020-8021

a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/acces…

Fix: 2.10.5+
Fix from $1,600 2020-05-19
Debian Linux HIGH 7.8
CVE-2020-5291

Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2`…

Fix: 0.4.1+
Fix from $1,950 2020-03-31
Debian Linux HIGH 7.5
CVE-2019-19728

SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.

Fix: 18.08.9 / 19.05.5+
Fix from $1,950 2020-01-13
Debian Linux HIGH 7.8
CVE-2013-2016

A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the vi…

Fix: after 1.4.2
Fix from $1,950 2019-12-30
Debian Linux MEDIUM 6.5
CVE-2019-19783

An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or cert…

Fix: 2.5.15 / 3.0.13+
Fix from $1,600 2019-12-16
Debian Linux MEDIUM 5.3
CVE-2012-1104

A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.

No fix yet
Fix from $1,600 2019-12-05
Debian Linux MEDIUM 6.5
CVE-2013-2625

An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1…

Fix: 2.0.8 / 2.1.4+
Fix from $1,600 2019-11-27
Debian Linux MEDIUM 6.7
CVE-2011-2910

The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping …

Fix: 0.0.8-13+
Fix from $1,600 2019-11-15
Debian Linux HIGH 8.8
CVE-2010-4664

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their…

Fix: 0.4.2+
Fix from $1,950 2019-11-13
Debian Linux HIGH 7.3
CVE-2013-2012

autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.

Fix: 21.5.8+
Fix from $1,950 2019-10-31
Debian Linux CRITICAL 9.8
CVE-2019-18425

An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. Ther…

Fix: after 4.12.1
Fix from $2,300 2019-10-31
Debian Linux MEDIUM 5.5
CVE-2015-9267

Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This al…

Fix: 2.49+
Fix from $1,600 2018-10-01
Debian Linux HIGH 7.8
CVE-2018-10906

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root use…

Fix: 2.9.8 / 3.2.5+
Fix from $1,950 2018-07-24
Debian Linux HIGH 7.8
CVE-2017-0358

Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe…

Fix: after 2016.2.22
Fix from $1,950 2018-04-13
Debian Linux HIGH 8.8
CVE-2017-9324

In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable o…

Fix: after 5.0.19
Fix from $1,950 2017-06-12
Debian Linux HIGH 7.5
CVE-2015-8467

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x befor…

Fix: 4.1.22 / 4.2.7+
Fix from $1,950 2015-12-29
Debian Linux HIGH 7.2
CVE-2014-3689

The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecifie…

Fix: after 2.1.3
Fix from $1,950 2014-11-14
Debian Linux MEDIUM 6.5
CVE-2011-1526

ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return valu…

Fix: 1.0.1+
Fix from $1,600 2011-07-11
Debian Linux HIGH 7.2
CVE-2007-2444

Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and…

Patch available
Fix from $1,950 2007-05-14