Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.5
CVE-2014-0021

Chrony before 1.29.1 has traffic amplification in cmdmon protocol

Fix: 1.29+
Fix from $1,950 2019-11-15
Debian Linux MEDIUM 5.9
CVE-2013-4584

Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_…

Fix: 2.1+
Fix from $1,600 2019-11-15
Debian Linux MEDIUM 6.5
CVE-2018-12207

Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to …

Fix: after 15.0.1
Fix from $1,600 2019-11-14
Debian Linux MEDIUM 6.0
CVE-2019-11139

Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentiall…

Mitigation only
Fix from $1,600 2019-11-14
Debian Linux CRITICAL 9.8
CVE-2011-1930EPSS 21%

In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker …

Fix: 1.5.25+
Fix from $2,300 2019-11-14
Debian Linux HIGH 7.8
CVE-2011-1145

The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE para…

Fix: after 2.2.14
Fix from $1,950 2019-11-14
Debian Linux HIGH 7.8
CVE-2011-1588

Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.

Patch available
Fix from $1,950 2019-11-14
Debian Linux MEDIUM 5.5
CVE-2011-1488

A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local a…

Fix: 5.7.6+
Fix from $1,600 2019-11-14
Debian Linux MEDIUM 5.5
CVE-2011-1489

A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output…

Fix: 5.7.6+
Fix from $1,600 2019-11-14
Debian Linux MEDIUM 5.5
CVE-2011-1490

A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output …

Fix: 5.7.6+
Fix from $1,600 2019-11-14
Debian Linux HIGH 7.8
CVE-2011-1070

v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mod…

Fix: 0.1.10+
Fix from $1,950 2019-11-14
Debian Linux MEDIUM 6.1
CVE-2011-0544

phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.

Fix: after 3.0.6
Fix from $1,600 2019-11-14
Debian Linux HIGH 7.5
CVE-2010-5108

Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and res…

Mitigation only
Fix from $1,950 2019-11-13
Debian Linux HIGH 8.8
CVE-2010-4664

In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their…

Fix: 0.4.2+
Fix from $1,950 2019-11-13
Debian Linux MEDIUM 5.5
CVE-2010-4817

pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.

Fix: 0.3.5+
Fix from $1,600 2019-11-13
Debian Linux HIGH 7.8
CVE-2010-4661

udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

Fix: 1.0.3+
Fix from $1,950 2019-11-13
Debian Linux HIGH 7.8
CVE-2010-4654

poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

Fix: 0.16.3+
Fix from $1,950 2019-11-13
Debian Linux MEDIUM 6.5
CVE-2010-4653

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

Fix: 0.16.3+
Fix from $1,600 2019-11-13
Debian Linux CRITICAL 9.8
CVE-2010-4533

offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed proto…

Fix: 6.3.4+
Fix from $2,300 2019-11-13
Debian Linux MEDIUM 5.9
CVE-2010-4532

offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle …

Fix: 6.3.2+
Fix from $1,600 2019-11-13
Debian Linux MEDIUM 6.5
CVE-2012-4385

letodms 3.3.6 has CSRF via change password

No fix yet
Fix from $1,600 2019-11-13
Debian Linux MEDIUM 6.1
CVE-2012-4384

letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar

Fix: after 3.3.11
Fix from $1,600 2019-11-13
Debian Linux HIGH 7.8
CVE-2019-18397

A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to caus…

Fix: after 1.0.7
Fix from $1,950 2019-11-13
Debian Linux HIGH 8.8
CVE-2010-3844

An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.

Patch available
Fix from $1,950 2019-11-12
Debian Linux MEDIUM 5.5
CVE-2010-3440

babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker…

Fix: 2.0.11+
Fix from $1,600 2019-11-12
Debian Linux CRITICAL 9.8
CVE-2010-3438

libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing…

Fix: 6.32+
Fix from $2,300 2019-11-12
Debian Linux MEDIUM 6.5
CVE-2010-3439

It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download co…

No fix yet
Fix from $1,600 2019-11-12
Debian Linux HIGH 7.5
CVE-2012-1572

OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space

Patch available
Fix from $1,950 2019-11-12
Debian Linux HIGH 7.8
CVE-2011-3618

atop: symlink attack possible due to insecure tempfile handling

Patch available
Fix from $1,950 2019-11-12
Debian Linux CRITICAL 9.8
CVE-2008-7291

gri before 2.12.18 generates temporary files in an insecure way.

Fix: 2.12.18+
Fix from $2,300 2019-11-08