Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
Debian Linux CRITICAL 10.0
CVE-2024-42472

Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app us…

Fix: 1.14.10 / 1.15.10+
Fix from $2,300 2024-08-15
Debian Linux HIGH 8.8
CVE-2023-43655

Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed …

Fix: 1.10.27 / 2.2.21+
Fix from $1,950 2023-09-29
Debmany HIGH 7.8
CVE-2023-27635

debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is…

Mitigation only
Fix from $1,950 2023-03-05
Debian Linux HIGH 8.8
CVE-2022-31086

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Debian Linux HIGH 7.8
CVE-2022-31087

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Debian Linux MEDIUM 5.3
CVE-2022-31088

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,600 2022-06-27
Debian Linux HIGH 8.8
CVE-2021-29454

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.…

Fix: 3.1.42 / 4.0.2+
Fix from $1,950 2022-01-10
Debian Linux HIGH 7.5
CVE-2021-32558EPSS 9%

An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Aster…

Fix: 13.38.3 / 16.19.1+
Fix from $1,950 2021-07-30
Debian Linux MEDIUM 5.9
CVE-2019-25031

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HT…

Fix: 1.9.5+
Fix from $1,600 2021-04-27
Debian Linux MEDIUM 5.3
CVE-2020-36308

Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading ti…

Fix: 4.0.7 / 4.1.1+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 5.3
CVE-2021-28963

Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters.

Fix: 3.2.1+
Fix from $1,600 2021-03-22
Debian Linux HIGH 8.2
CVE-2021-21381

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before versi…

Fix: 1.10.2+
Fix from $1,950 2021-03-11
Debian Linux HIGH 8.8
CVE-2021-21261

Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` ser…

Fix: 1.8.5 / 1.10.0+
Fix from $1,950 2021-01-14
Debian Linux HIGH 7.0
CVE-2020-15238

Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argume…

Fix: 2.1.4+
Fix from $1,950 2020-10-27
Debian Linux CRITICAL 9.8
CVE-2020-15227EPSS 35%

Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters…

Fix: 2.0.19 / 2.1.13+
Fix from $2,300 2020-10-01
Debian Linux MEDIUM 5.9
CVE-2020-14928

evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds…

Fix: after 3.36.3
Fix from $1,600 2020-07-17
Debian Linux MEDIUM 5.9
CVE-2020-14954

Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS"…

Fix: 1.14.4 / 20200619+
Fix from $1,600 2020-06-21
Debian Linux MEDIUM 6.5
CVE-2020-12108

/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.

Fix: 2.1.31+
Fix from $1,600 2020-05-06
Debian Linux MEDIUM 6.1
CVE-2019-18860EPSS 6%

Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.

Fix: 4.9+
Fix from $1,600 2020-03-20
Debian Linux CRITICAL 9.8
CVE-2014-4172EPSS 6%

A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.…

Fix: 1.0.2 / 1.3.3+
Fix from $2,300 2020-01-24
Debian Linux HIGH 7.8
CVE-2010-4654

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

Fix: 0.16.3+
Fix from $1,950 2019-11-13
Debian Linux HIGH 7.5
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. T…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux HIGH 7.5
CVE-2019-8323

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux HIGH 7.5
CVE-2019-8325

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence in…

Fix: after 3.0.2
Fix from $1,950 2019-06-17
Debian Linux HIGH 8.8
CVE-2017-18266

The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER enviro…

Fix: 1.1.3+
Fix from $1,950 2018-05-10
Debian Linux CRITICAL 9.8
CVE-2017-0372EPSS 12%

Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities.

Fix: after 1.23.15
Fix from $2,300 2018-04-13
Debian Linux HIGH 7.5
CVE-2018-6519

The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for…

Fix: 1.10.4 / 2.3.5+
Fix from $1,950 2018-02-02
Debian Linux HIGH 8.8
CVE-2017-17511

KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attac…

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17514

boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote …

Mitigation only
Fix from $1,950 2017-12-14
Debian Linux HIGH 8.8
CVE-2017-17515

etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might all…

Mitigation only
Fix from $1,950 2017-12-14