Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Advanced Package Tool HIGH 10.0
CVE-2009-1300

apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones fo…

Mitigation only
Fix from $1,950 2009-04-16
Debian Linux HIGH 7.8
CVE-2009-1270EPSS 5%

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) c…

Fix: 0.95+
Fix from $1,950 2009-04-08
Nss Ldap MEDIUM 5.5
CVE-2009-1073

nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for …

Fix: 0.6.8+
Fix from $1,600 2009-03-31
Debian Linux CRITICAL 9.8
CVE-2009-1151 KEVEPSS 95%

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitr…

Fix: 2.11.9.5 / 3.1.3.1+
Fix from $2,300 2009-03-26
Debian Linux MEDIUM 6.3
CVE-2009-0784

Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel …

Patch available
Fix from $1,600 2009-03-25
Horde MEDIUM 6.4
CVE-2009-0932EPSS 46%

Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attacke…

Mitigation only
Fix from $1,600 2009-03-17
Debian Linux MEDIUM 6.8
CVE-2009-0040

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent a…

Fix: 1.0.43 / 1.2.35+
Fix from $1,600 2009-02-22
Debian Linux HIGH 9.3
CVE-2009-0385EPSS 7%

Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute a…

Fix: 0.6.3+
Fix from $1,950 2009-02-02
Debian Linux MEDIUM 5.0
CVE-2008-5907

The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the val…

Fix: 1.0.42 / 1.2.34+
Fix from $1,600 2009-01-15
Shadow HIGH 7.2
CVE-2008-5394

/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrar…

No fix yet
Fix from $1,950 2008-12-09
Debian Linux HIGH 7.5
CVE-2008-5183EPSS 9%

cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large numb…

Fix: 10.5.6+
Fix from $1,950 2008-11-21
Mailscanner MEDIUM 6.9
CVE-2008-5140

trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack …

Mitigation only
Fix from $1,600 2008-11-18
Ltp MEDIUM 6.9
CVE-2008-5145

ltpmenu in ltp 20060918 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/runltp.mainmenu.##### temporary file.

Mitigation only
Fix from $1,600 2008-11-18
Os Prober MEDIUM 6.2
CVE-2008-5135

os-prober in os-prober 1.17 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/mounted-map or (2) /tmp/raided-map t…

Mitigation only
Fix from $1,600 2008-11-18
Initramfs Tools MEDIUM 5.5
CVE-2008-4996

init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via a symlink attack on the /tmp/initramfs.debug temporary file. NOTE:…

No fix yet
Fix from $1,600 2008-11-07
Newsgate MEDIUM 6.9
CVE-2008-4975

mkmailpost in newsgate 1.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mmp##### temporary file.

No fix yet
Fix from $1,600 2008-11-06
Myspell MEDIUM 6.9
CVE-2008-4973

i2myspell in myspell 3.1 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/i2my#####.1 and (2) /tmp/i2my#####.2 tempor…

No fix yet
Fix from $1,600 2008-11-06
Dpkg Cross MEDIUM 6.9
CVE-2008-4950

gccross in dpkg-cross 2.3.0 allows local users to overwrite arbitrary files via a symlink attack on the tmp/gccross2.log temporary file. NOTE: the v…

No fix yet
Fix from $1,600 2008-11-05
Debian Linux HIGH 10.0
CVE-2008-4796EPSS 9%

The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamat…

Fix: 2.6.3 / 4.2.2+
Fix from $1,950 2008-10-30
Feta HIGH 7.2
CVE-2008-4440

The to-upgrade plugin in feta 1.4.16 allows local users to overwrite arbitrary files via a symlink on the (1) /tmp/feta.install.$USER and (2) /tmp/fe…

Mitigation only
Fix from $1,950 2008-10-03
Debian Linux HIGH 7.5
CVE-2008-4359

lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, w…

Fix: 1.4.20+
Fix from $1,950 2008-10-03
Debian Linux HIGH 7.5
CVE-2008-4360

mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filenam…

Fix: 1.4.20+
Fix from $1,950 2008-10-03
Xsabre HIGH 7.2
CVE-2008-4406

A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to delete or overwrite arbitrary files via a symlink attac…

Mitigation only
Fix from $1,950 2008-10-03
Python Dns MEDIUM 6.4
CVE-2008-4126

PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs f…

Fix: after 2.3.1-4
Fix from $1,600 2008-09-18
Python Dns MEDIUM 6.4
CVE-2008-4099

PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier…

Fix: after 2.3.1-3
Fix from $1,600 2008-09-18
Debian Linux HIGH 10.0
CVE-2008-3529EPSS 23%

Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a …

Fix: 2.7.0 / 3.0+
Fix from $1,950 2008-09-12
Debian Linux MEDIUM 5.0
CVE-2008-3912

libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to…

Fix: 0.94+
Fix from $1,600 2008-09-11
Debian Linux MEDIUM 5.0
CVE-2008-3913

Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspec…

Fix: 0.94+
Fix from $1,600 2008-09-11
Honeyd Common MEDIUM 6.9
CVE-2008-3928

test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file.

Mitigation only
Fix from $1,600 2008-09-04
Citadel Server MEDIUM 6.9
CVE-2008-3930

migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

Mitigation only
Fix from $1,600 2008-09-04