Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 6.1
CVE-2012-1114

A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_…

Mitigation only
Fix from $1,600 2019-12-05
Debian Linux MEDIUM 6.1
CVE-2012-1115

A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.

Mitigation only
Fix from $1,600 2019-12-05
Debian Linux MEDIUM 5.3
CVE-2012-1104

A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.

No fix yet
Fix from $1,600 2019-12-05
Debian Linux MEDIUM 5.5
CVE-2013-0326

OpenStack nova base images permissions are world readable

Mitigation only
Fix from $1,600 2019-12-05
Debian Linux CRITICAL 9.8
CVE-2013-2745

An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0

Fix: 1.1.0+
Fix from $2,300 2019-12-04
Devscripts HIGH 8.8
CVE-2013-7325

An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.

Fix: 2.13.19+
Fix from $1,950 2019-12-03
Debian Linux MEDIUM 5.3
CVE-2015-7542

A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates.

Fix: after 4.12.0
Fix from $1,600 2019-12-03
Debian Linux HIGH 7.5
CVE-2013-2106

webauth before 4.6.1 has authentication credential disclosure

Fix: 4.6.1+
Fix from $1,950 2019-12-03
Debian Linux HIGH 7.5
CVE-2012-4428EPSS 10%

openslp: SLPIntersectStringList()' Function has a DoS vulnerability

Mitigation only
Fix from $1,950 2019-12-02
Debian Linux MEDIUM 5.5
CVE-2019-19479

An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsin…

Fix: after 0.19.0
Fix from $1,600 2019-12-01
Debian Linux MEDIUM 5.9
CVE-2015-0837

The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differe…

Fix: 1.4.19 / 1.6.3+
Fix from $1,600 2019-11-29
Debian Linux CRITICAL 9.8
CVE-2011-2523EPSS 96%

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

No fix yet
Fix from $2,300 2019-11-27
Debian Linux MEDIUM 5.3
CVE-2011-2515

PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and ex…

Mitigation only
Fix from $1,600 2019-11-27
Debian Linux MEDIUM 6.5
CVE-2013-2625

An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1…

Fix: 2.0.8 / 2.1.4+
Fix from $1,600 2019-11-27
Debian Linux HIGH 8.1
CVE-2012-2248

An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.

Mitigation only
Fix from $1,950 2019-11-27
Debian Linux HIGH 7.8
CVE-2011-2187

xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows loc…

Fix: 5.14+
Fix from $1,950 2019-11-27
Debian Linux MEDIUM 6.5
CVE-2011-4350EPSS 16%

Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain co…

No fix yet
Fix from $1,600 2019-11-26
Debian Linux CRITICAL 9.8
CVE-2011-4120

Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured…

Fix: 2.10+
Fix from $2,300 2019-11-26
Debian Linux HIGH 7.5
CVE-2011-4082

A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remot…

Fix: 0.9.8+
Fix from $1,950 2019-11-26
Debian Linux HIGH 8.8
CVE-2011-3631

Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done i…

Fix: 0.1.2+
Fix from $1,950 2019-11-26
Debian Linux HIGH 7.1
CVE-2011-3632

Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.

Fix: 0.1.2+
Fix from $1,950 2019-11-26
Debian Linux HIGH 8.8
CVE-2011-3630

Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are pr…

Fix: 0.1.2+
Fix from $1,950 2019-11-26
Debian Linux MEDIUM 6.5
CVE-2011-3617

Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.

Fix: after 1.8.2
Fix from $1,600 2019-11-26
Debian Linux HIGH 7.5
CVE-2011-3596EPSS 11%

Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.

Fix: 1.0.4.1+
Fix from $1,950 2019-11-26
Debian Linux HIGH 7.5
CVE-2015-1396

A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a pa…

Fix: 2.7.4+
Fix from $1,950 2019-11-25
Debian Linux MEDIUM 5.5
CVE-2012-5644

libuser has information disclosure when moving user's home directory

Fix: 0.59+
Fix from $1,600 2019-11-25
Debian Linux MEDIUM 6.5
CVE-2012-5521

quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

Mitigation only
Fix from $1,600 2019-11-25
Debian Linux CRITICAL 9.8
CVE-2014-6310

Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.

Patch available
Fix from $2,300 2019-11-22
Debian Linux CRITICAL 9.8
CVE-2014-6311

generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.

Fix: after 6.2.6
Fix from $2,300 2019-11-22
Debian Linux HIGH 8.8
CVE-2019-18610EPSS 30%

An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenti…

Fix: 13.29.2 / 16.6.2+
Fix from $1,950 2019-11-22