clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure tempo…
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed …
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatur…
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
Dump Servlet information leak in jetty before 6.1.22.
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
WebApp JSP Snoop page XSS in jetty though 6.1.21.
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge…
There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to…
slim has NULL pointer dereference when using crypt() method from glibc 2.17
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
MiniDLNA has heap-based buffer overflow
evince is missing a check on number of pages which can lead to a segmentation fault
MiniUPnPd has information disclosure use of snprintf()
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.