Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Debian Linux CRITICAL 9.9
CVE-2025-0781

An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating…

Fix: after 2020.3.19
Fix from $2,300 2025-01-28
Debian Linux HIGH 7.4
CVE-2021-3563

A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password co…

No fix yet
Fix from $1,950 2022-08-26
Debian Linux HIGH 7.8
CVE-2022-31087

LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t…

Fix: 8.0+
Fix from $1,950 2022-06-27
Debian Linux MEDIUM 6.5
CVE-2022-0577

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1.

Fix: 2.6.1+
Fix from $1,600 2022-03-02
Debian Linux HIGH 8.8
CVE-2020-25722

Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause…

Fix: 4.13.14 / 4.14.10+
Fix from $1,950 2022-02-18
Debian Linux HIGH 7.8
CVE-2021-3560 KEVEPSS 22%

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r…

Fix: 0.119+
Fix from $1,950 2022-02-16
Debian Linux HIGH 7.5
CVE-2021-35197

In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot accou…

Fix: 1.31.15 / 1.35.3+
Fix from $1,950 2021-07-02
Debian Linux HIGH 7.5
CVE-2020-3811

qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.

Patch available
Fix from $1,950 2020-05-26
Debian Linux CRITICAL 9.8
CVE-2020-8086

The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() f…

Fix: after 2020-01-27
Fix from $2,300 2020-01-28
Debian Linux CRITICAL 9.8
CVE-2012-6094

cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

Fix: 1.5.4-1.1+
Fix from $2,300 2019-12-20
Debian Linux MEDIUM 6.5
CVE-2011-3617

Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.

Fix: after 1.8.2
Fix from $1,600 2019-11-26
Debian Linux HIGH 7.8
CVE-2011-1070

v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mod…

Fix: 0.1.10+
Fix from $1,950 2019-11-14
Debian Linux HIGH 7.5
CVE-2009-3723

asterisk allows calls on prohibited networks

Fix: 1.6.1.8+
Fix from $1,950 2019-10-29
Debian Linux CRITICAL 9.8
CVE-2019-15941

OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorizat…

Fix: after 2.0.5
Fix from $2,300 2019-09-25
Debian Linux MEDIUM 5.3
CVE-2018-20685

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. …

Fix: after 7.9
Fix from $1,600 2019-01-10
Debian Linux MEDIUM 6.5
CVE-2017-12197

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di…

Fix: after 1.8
Fix from $1,600 2018-01-18