Vulnerability index

Browse CVEs

29 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
HIGH 7.8 CVE-2023-26604 systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "sys… Debian Linux 246.7+ Fix from $1,9502023-03-03 HIGH 7.8 CVE-2023-22809EPSS 55% In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VIS… Debian Linux 1.9.12 / 13.4+ Fix from $1,9502023-01-18 HIGH 8.8 CVE-2022-39286 Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code exec… Debian Linux 4.11.2+ Fix from $1,9502022-10-26 HIGH 8.8 CVE-2019-9971 PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an attacker to gain root privileges by using sudo with the tc… Debian Linux No fix yet Fix from $1,9502022-06-07 HIGH 8.8 CVE-2022-21699 IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python prog… Debian Linux 7.16.3 / 7.31.1+ Fix from $1,9502022-01-19 MEDIUM 6.5 CVE-2021-43528 Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not receive ch… Debian Linux 91.4.0+ Fix from $1,6002021-12-08 HIGH 8.8 CVE-2021-32739 Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for repor… Debian Linux 2.11.10 / 2.12.5+ Fix from $1,9502021-07-15 HIGH 7.8 CVE-2017-20002 The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty. This allows local user… Shadow No fix yet Fix from $1,9502021-03-17 HIGH 8.8 CVE-2020-29481 An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not r… Debian Linux after 4.14.0 Fix from $1,9502020-12-15 MEDIUM 5.5 CVE-2020-3812 qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and d… Debian Linux Patch available Fix from $1,6002020-05-26 MEDIUM 5.3 CVE-2020-8021 a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/acces… Debian Linux 2.10.5+ Fix from $1,6002020-05-19 HIGH 7.8 CVE-2020-5291 Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2`… Debian Linux 0.4.1+ Fix from $1,9502020-03-31 HIGH 7.5 CVE-2019-19728 SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges. Debian Linux 18.08.9 / 19.05.5+ Fix from $1,9502020-01-13 HIGH 7.8 CVE-2013-2016 A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the vi… Debian Linux after 1.4.2 Fix from $1,9502019-12-30 MEDIUM 6.5 CVE-2019-19783 An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or cert… Debian Linux 2.5.15 / 3.0.13+ Fix from $1,6002019-12-16 MEDIUM 5.3 CVE-2012-1104 A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed. Debian Linux No fix yet Fix from $1,6002019-12-05 MEDIUM 6.5 CVE-2013-2625 An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1… Debian Linux 2.0.8 / 2.1.4+ Fix from $1,6002019-11-27 MEDIUM 6.7 CVE-2011-2910 The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping … Debian Linux 0.0.8-13+ Fix from $1,6002019-11-15 HIGH 8.8 CVE-2010-4664 In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their… Debian Linux 0.4.2+ Fix from $1,9502019-11-13 HIGH 7.3 CVE-2013-2012 autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory. Debian Linux 21.5.8+ Fix from $1,9502019-10-31 CRITICAL 9.8 CVE-2019-18425 An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. Ther… Debian Linux after 4.12.1 Fix from $2,3002019-10-31 MEDIUM 5.5 CVE-2015-9267 Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This al… Debian Linux 2.49+ Fix from $1,6002018-10-01 HIGH 7.8 CVE-2018-10906 In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root use… Debian Linux 2.9.8 / 3.2.5+ Fix from $1,9502018-07-24 HIGH 7.8 CVE-2017-0358 Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe… Debian Linux after 2016.2.22 Fix from $1,9502018-04-13 HIGH 8.8 CVE-2017-9324 In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable o… Debian Linux after 5.0.19 Fix from $1,9502017-06-12 HIGH 7.5 CVE-2015-8467 The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x befor… Debian Linux 4.1.22 / 4.2.7+ Fix from $1,9502015-12-29 HIGH 7.2 CVE-2014-3689 The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecifie… Debian Linux after 2.1.3 Fix from $1,9502014-11-14 MEDIUM 6.5 CVE-2011-1526 ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return valu… Debian Linux 1.0.1+ Fix from $1,6002011-07-11 HIGH 7.2 CVE-2007-2444 Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and… Debian Linux Patch available Fix from $1,9502007-05-14