Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.0
CVE-2011-4362EPSS 23%

Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 b…

Fix: 1.4.30+
Fix from $1,600 2011-12-24
Debian Linux HIGH 7.8
CVE-2011-2749EPSS 39%

The server in ISC DHCP 3.x and 4.x before 4.2.2, 3.1-ESV before 3.1-ESV-R3, and 4.1-ESV before 4.1-ESV-R3 allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2011-08-15
Debian Linux MEDIUM 6.8
CVE-2011-2522EPSS 10%

Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.10 allow remote attack…

Fix: 3.3.16 / 3.4.14+
Fix from $1,600 2011-07-29
Debian Linux HIGH 7.5
CVE-2011-2688EPSS 6%

SQL injection vulnerability in mysql/mysql-auth.pl in the mod_authnz_external module 3.2.5 and earlier for the Apache HTTP Server allows remote attac…

Fix: after 3.2.5
Fix from $1,950 2011-07-28
Debian Linux MEDIUM 6.5
CVE-2011-1526

ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return valu…

Fix: 1.0.1+
Fix from $1,600 2011-07-11
Debian Linux HIGH 7.5
CVE-2011-0997EPSS 84%

dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute…

Patch available
Fix from $1,950 2011-04-08
Tex Common MEDIUM 6.8
CVE-2011-1400

The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/…

Mitigation only
Fix from $1,600 2011-03-25
Shadow MEDIUM 6.4
CVE-2011-0721

Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via th…

Mitigation only
Fix from $1,600 2011-02-19
Dpkg MEDIUM 6.8
CVE-2011-0402

dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files via a symlink attack on unspecified fil…

Fix: after 1.14.30
Fix from $1,600 2011-01-11
Dpkg MEDIUM 6.8
CVE-2010-1679

Directory traversal vulnerability in dpkg-source in dpkg before 1.14.31 and 1.15.x allows user-assisted remote attackers to modify arbitrary files vi…

Fix: after 1.14.30
Fix from $1,600 2011-01-11
Debian Linux CRITICAL 9.8
CVE-2010-4344 KEVEPSS 72%

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SM…

Fix: 4.70+
Fix from $2,300 2010-12-14
Debian Linux HIGH 7.8
CVE-2010-4345 KEVEPSS 18%

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration …

Fix: after 4.72
Fix from $1,950 2010-12-14
Mono Debugger MEDIUM 6.9
CVE-2010-3369

The (1) mdb and (2) mdb-symbolreader scripts in mono-debugger 2.4.3, and other versions before 2.8.1, place a zero-length directory name in the LD_LI…

Patch available
Fix from $1,600 2010-10-20
Debian Linux MEDIUM 6.8
CVE-2010-2527EPSS 6%

Multiple buffer overflows in demo programs in FreeType before 2.4.0 allow remote attackers to cause a denial of service (application crash) or possib…

Fix: 2.4.0+
Fix from $1,600 2010-08-19
Debian Linux MEDIUM 6.8
CVE-2010-2497EPSS 6%

Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly exe…

Fix: 2.4.0 / 10.6.5+
Fix from $1,600 2010-08-19
Pyftpd HIGH 7.5
CVE-2010-2073

auth_db_config.py in Pyftpd 0.8.4 contains hard-coded usernames and passwords for the (1) test, (2) user, and (3) roxon accounts, which allows remote…

Patch available
Fix from $1,950 2010-06-16
Dpkg HIGH 7.2
CVE-2004-2768

dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain…

No fix yet
Fix from $1,950 2010-06-08
Debian Linux MEDIUM 6.8
CVE-2010-1321EPSS 7%

The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as u…

Fix: 1.8.2+
Fix from $1,600 2010-05-19
Dpkg MEDIUM 5.8
CVE-2010-0396

Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted…

Fix: after 1.14.28
Fix from $1,600 2010-03-15
Lintian CRITICAL 9.8
CVE-2009-4013EPSS 6%

Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers …

Fix: 2.3.2+
Fix from $2,300 2010-02-02
Lintian HIGH 7.5
CVE-2009-4014

Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to hav…

Patch available
Fix from $1,950 2010-02-02
Lintian HIGH 7.5
CVE-2009-4015

Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacha…

Patch available
Fix from $1,950 2010-02-02
Debian Linux HIGH 8.8
CVE-2010-0012

Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbit…

Patch available
Fix from $1,950 2010-01-08
Debian Linux HIGH 7.5
CVE-2008-7220EPSS 13%

Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unkn…

Fix: 1.6.0.2+
Fix from $1,950 2009-09-13
Debian Linux MEDIUM 6.8
CVE-2009-1721

The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial o…

Fix: 10.5.8+
Fix from $1,600 2009-07-31
Debian Linux MEDIUM 5.8
CVE-2009-1888

The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, whe…

Fix: 3.2.13 / 3.3.6+
Fix from $1,600 2009-06-25
Libdbd Pg Perl MEDIUM 5.0
CVE-2009-1341

Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-depend…

Fix: after 1.4.9
Fix from $1,600 2009-04-30
Advanced Package Tool HIGH 10.0
CVE-2009-1358

apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has be…

Fix: after 0.7.20
Fix from $1,950 2009-04-21
Debian Linux HIGH 7.2
CVE-2009-1185EPSS 82%

udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NE…

Fix: 141+
Fix from $1,950 2009-04-17
Debian Linux HIGH 7.5
CVE-2009-0946EPSS 9%

Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in cert…

Fix: after 10.6.4
Fix from $1,950 2009-04-17