duplicity 0.6.24 has improper verification of SSL certificates
Orca has arbitrary code execution due to insecure Python module load
lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.
HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a cr…
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_…
A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
OpenStack nova base images permissions are world readable
openslp: SLPIntersectStringList()' Function has a DoS vulnerability
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and ex…
An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain co…
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
PostfixAdmin 2.3.4 has multiple XSS vulnerabilities
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An i…
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.…
9base 1:6-6 and 1:6-7 insecurely creates temporary files which results in predictable filenames.
foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode w…
uzbl: Information disclosure via world-readable cookies storage file
Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentiall…
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and res…
letodms 3.3.6 has CSRF via change password
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download co…
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.