Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
CRITICAL 10.0 CVE-2024-42472 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app us… Debian Linux 1.14.10 / 1.15.10+ Fix from $2,3002024-08-15 HIGH 8.8 CVE-2023-43655 Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed … Debian Linux 1.10.27 / 2.2.21+ Fix from $1,9502023-09-29 HIGH 7.8 CVE-2023-27635 debmany in debian-goodies 0.88.1 allows attackers to execute arbitrary shell commands (because of an eval call) via a crafted .deb file. (The path is… Debmany Mitigation only Fix from $1,9502023-03-05 HIGH 8.8 CVE-2022-31086 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,9502022-06-27 HIGH 7.8 CVE-2022-31087 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,9502022-06-27 MEDIUM 5.3 CVE-2022-31088 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,6002022-06-27 HIGH 8.8 CVE-2021-29454 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.… Debian Linux 3.1.42 / 4.0.2+ Fix from $1,9502022-01-10 HIGH 7.5 CVE-2021-32558EPSS 9% An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x before 18.5.1, and Certified Aster… Debian Linux 13.38.3 / 16.19.1+ Fix from $1,9502021-07-30 MEDIUM 5.9 CVE-2019-25031 Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HT… Debian Linux 1.9.5+ Fix from $1,6002021-04-27 MEDIUM 5.3 CVE-2020-36308 Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading ti… Debian Linux 4.0.7 / 4.1.1+ Fix from $1,6002021-04-06 MEDIUM 5.3 CVE-2021-28963 Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled parameters. Debian Linux 3.2.1+ Fix from $1,6002021-03-22 HIGH 8.2 CVE-2021-21381 Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before versi… Debian Linux 1.10.2+ Fix from $1,9502021-03-11 HIGH 8.8 CVE-2021-21261 Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovered in the `flatpak-portal` ser… Debian Linux 1.8.5 / 1.10.0+ Fix from $1,9502021-01-14 HIGH 7.0 CVE-2020-15238 Blueman is a GTK+ Bluetooth Manager. In Blueman before 2.1.4, the DhcpClient method of the D-Bus interface to blueman-mechanism is prone to an argume… Debian Linux 2.1.4+ Fix from $1,9502020-10-27 CRITICAL 9.8 CVE-2020-15227EPSS 35% Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters… Debian Linux 2.0.19 / 2.1.13+ Fix from $2,3002020-10-01 MEDIUM 5.9 CVE-2020-14928 evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds… Debian Linux after 3.36.3 Fix from $1,6002020-07-17 MEDIUM 5.9 CVE-2020-14954 Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS"… Debian Linux 1.14.4 / 20200619+ Fix from $1,6002020-06-21 MEDIUM 6.5 CVE-2020-12108 /options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection. Debian Linux 2.1.31+ Fix from $1,6002020-05-06 MEDIUM 6.1 CVE-2019-18860EPSS 6% Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. Debian Linux 4.9+ Fix from $1,6002020-03-20 CRITICAL 9.8 CVE-2014-4172EPSS 6% A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.… Debian Linux 1.0.2 / 1.3.3+ Fix from $2,3002020-01-24 HIGH 7.8 CVE-2010-4654 poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. Debian Linux 0.16.3+ Fix from $1,9502019-11-13 HIGH 7.5 CVE-2019-8322 An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. T… Debian Linux after 3.0.2 Fix from $1,9502019-06-17 HIGH 7.5 CVE-2019-8323 An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is… Debian Linux after 3.0.2 Fix from $1,9502019-06-17 HIGH 7.5 CVE-2019-8325 An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence in… Debian Linux after 3.0.2 Fix from $1,9502019-06-17 HIGH 8.8 CVE-2017-18266 The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER enviro… Debian Linux 1.1.3+ Fix from $1,9502018-05-10 CRITICAL 9.8 CVE-2017-0372EPSS 12% Parameters injection in the SyntaxHighlight extension of Mediawiki before 1.23.16, 1.27.3 and 1.28.2 might result in multiple vulnerabilities. Debian Linux after 1.23.15 Fix from $2,3002018-04-13 HIGH 7.5 CVE-2018-6519 The SAML2 library before 1.10.4, 2.x before 2.3.5, and 3.x before 3.1.1 in SimpleSAMLphp has a Regular Expression Denial of Service vulnerability for… Debian Linux 1.10.4 / 2.3.5+ Fix from $1,9502018-02-02 HIGH 8.8 CVE-2017-17511 KildClient 3.1.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attac… Debian Linux Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17514 boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote … Debian Linux Mitigation only Fix from $1,9502017-12-14 HIGH 8.8 CVE-2017-17515 etc/ObjectList in Metview 4.7.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might all… Debian Linux Mitigation only Fix from $1,9502017-12-14