Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 10.0
CVE-2008-1673EPSS 7%

The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (…

Patch available
Fix from $1,950 2008-06-10
Aptlinex HIGH 7.2
CVE-2008-1901

aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the gambas-apt.lock temporary file.

Mitigation only
Fix from $1,950 2008-04-22
Aptlinex MEDIUM 5.0
CVE-2008-1902

The GUI for aptlinex before 0.91 does not sufficiently warn the user of potentially dangerous actions, which allows remote attackers to remove or mod…

Mitigation only
Fix from $1,600 2008-04-22
Debian Linux MEDIUM 5.5
CVE-2008-1567

phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp…

Fix: 2.11.5.1+
Fix from $1,600 2008-03-31
Debian Linux CRITICAL 9.8
CVE-2008-0062EPSS 10%

KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of servic…

Fix: after 1.6.3
Fix from $2,300 2008-03-19
Apt Listchanges HIGH 7.2
CVE-2008-0302

Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious…

Fix: after 2.81
Fix from $1,950 2008-01-17
Debian Linux MEDIUM 5.0
CVE-2007-6284

The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containi…

Patch available
Fix from $1,600 2008-01-12
Unp HIGH 10.0
CVE-2007-6610

unp 1.0.12, and other versions before 1.0.14, does not properly escape file names, which might allow context-dependent attackers to execute arbitrary…

Fix: after 1.0.12
Fix from $1,950 2008-01-03
Debian Linux HIGH 7.5
CVE-2007-6353

Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a he…

Fix: 0.16+
Fix from $1,950 2007-12-20
Debian Linux MEDIUM 6.5
CVE-2007-6170

SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x b…

Fix: 1.2.25 / 1.4.15+
Fix from $1,600 2007-11-30
Debian Linux HIGH 7.2
CVE-2007-5729

The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_…

Mitigation only
Fix from $1,950 2007-10-30
Debian Linux HIGH 7.2
CVE-2007-5730

Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data i…

Mitigation only
Fix from $1,950 2007-10-30
Debian Linux HIGH 7.2
CVE-2007-5365EPSS 80%

Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based…

Patch available
Fix from $1,950 2007-10-11
Debian Goodies HIGH 7.2
CVE-2007-3912

checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a ru…

Patch available
Fix from $1,950 2007-09-10
Reprepro MEDIUM 5.0
CVE-2007-4739

reprepro 1.3.0 through 2.2.3 does not properly verify signatures when updating repositories, which allows remote attackers to construct and distribut…

Patch available
Fix from $1,600 2007-09-06
Debian Linux HIGH 7.5
CVE-2007-4476EPSS 15%

Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."

Fix: 1.19+
Fix from $1,950 2007-09-05
Debian Linux MEDIUM 6.8
CVE-2007-3387EPSS 9%

Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf…

Fix: 0.5.91 / 2.8.2+
Fix from $1,600 2007-07-30
Gfax HIGH 7.2
CVE-2007-2839

gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.

Fix: after 0.4.2
Fix from $1,950 2007-07-05
Debian Linux HIGH 10.0
CVE-2007-2442EPSS 11%

The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary c…

Fix: after 1.6.1
Fix from $1,950 2007-06-26
Debian Linux HIGH 8.3
CVE-2007-2443

Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might …

Fix: after 1.6.1
Fix from $1,950 2007-06-26
Debian Linux HIGH 7.5
CVE-2007-3409

Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet w…

Fix: 0.60+
Fix from $1,950 2007-06-26
Debian Linux HIGH 7.8
CVE-2007-2833

Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, …

Mitigation only
Fix from $1,950 2007-06-21
Debian Linux HIGH 7.2
CVE-2007-2444

Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and…

Patch available
Fix from $1,950 2007-05-14
Debian Linux HIGH 10.0
CVE-2007-0956EPSS 30%

The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning…

Fix: 1.6.1+
Fix from $1,950 2007-04-06
Debian Linux HIGH 9.0
CVE-2007-0957EPSS 10%

Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Di…

Fix: 1.6.1+
Fix from $1,950 2007-04-06
Debian Linux HIGH 9.3
CVE-2007-1667

Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagi…

Fix: after 1.0.2
Fix from $1,950 2007-03-24
Apache MEDIUM 6.6
CVE-2006-7098

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when http…

Mitigation only
Fix from $1,600 2007-03-03
Debian Linux HIGH 7.5
CVE-2007-0897

Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of s…

Fix: 0.90 / 10.4.11+
Fix from $1,950 2007-02-16
Debian Linux HIGH 7.5
CVE-2007-0454EPSS 6%

Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code v…

Patch available
Fix from $1,950 2007-02-06
Debian Linux MEDIUM 6.8
CVE-2006-6942

Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1…

Fix: after 2.9.1
Fix from $1,600 2007-01-19