Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
CRITICAL 9.9 CVE-2025-0781 An attacker can bypass the sandboxing of Nasal scripts and arbitrarily write to any file path that the user has permission to modify at the operating… Debian Linux after 2020.3.19 Fix from $2,3002025-01-28 HIGH 7.4 CVE-2021-3563 A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password co… Debian Linux No fix yet Fix from $1,9502022-08-26 HIGH 7.8 CVE-2022-31087 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior t… Debian Linux 8.0+ Fix from $1,9502022-06-27 MEDIUM 6.5 CVE-2022-0577 Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository scrapy/scrapy prior to 2.6.1. Debian Linux 2.6.1+ Fix from $1,6002022-03-02 HIGH 8.8 CVE-2020-25722 Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause… Debian Linux 4.13.14 / 4.14.10+ Fix from $1,9502022-02-18 HIGH 7.8 CVE-2021-3560 KEVEPSS 22% It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the r… Debian Linux 0.119+ Fix from $1,9502022-02-16 HIGH 7.5 CVE-2021-35197 In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot accou… Debian Linux 1.31.15 / 1.35.3+ Fix from $1,9502021-07-02 HIGH 7.5 CVE-2020-3811 qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. Debian Linux Patch available Fix from $1,9502020-05-26 CRITICAL 9.8 CVE-2020-8086 The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() f… Debian Linux after 2020-01-27 Fix from $2,3002020-01-28 CRITICAL 9.8 CVE-2012-6094 cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system Debian Linux 1.5.4-1.1+ Fix from $2,3002019-12-20 MEDIUM 6.5 CVE-2011-3617 Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases. Debian Linux after 1.8.2 Fix from $1,6002019-11-26 HIGH 7.8 CVE-2011-1070 v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mod… Debian Linux 0.1.10+ Fix from $1,9502019-11-14 HIGH 7.5 CVE-2009-3723 asterisk allows calls on prohibited networks Debian Linux 1.6.1.8+ Fix from $1,9502019-10-29 CRITICAL 9.8 CVE-2019-15941 OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorizat… Debian Linux after 2.0.5 Fix from $2,3002019-09-25 MEDIUM 5.3 CVE-2018-20685 In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. … Debian Linux after 7.9 Fix from $1,6002019-01-10 MEDIUM 6.5 CVE-2017-12197 It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di… Debian Linux after 1.8 Fix from $1,6002018-01-18