Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2007-6745

clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

Mitigation only
Fix from $2,300 2019-11-07
Debian Linux HIGH 7.5
CVE-2013-1809

Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure tempo…

Fix: 3.4.0+
Fix from $1,950 2019-11-07
Debian Linux HIGH 7.5
CVE-2007-5743

viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.

No fix yet
Fix from $1,950 2019-11-07
Lintian MEDIUM 6.3
CVE-2013-1429

Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.

Fix: 2.5.10.5+
Fix from $1,600 2019-11-07
Debian Linux HIGH 7.5
CVE-2010-2450

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed …

Patch available
Fix from $1,950 2019-11-07
Debian Linux MEDIUM 5.5
CVE-2013-1425

ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.

Fix: 1.0.4+
Fix from $1,600 2019-11-07
Debian Linux HIGH 8.8
CVE-2019-3465

Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatur…

Fix: after 3.0.3
Fix from $1,950 2019-11-07
Debian Linux HIGH 7.4
CVE-2012-0051

Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.

No fix yet
Fix from $1,950 2019-11-07
Debian Linux HIGH 7.5
CVE-2019-18804

DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.

No fix yet
Fix from $1,950 2019-11-07
Debian Linux HIGH 7.5
CVE-2009-5045

Dump Servlet information leak in jetty before 6.1.22.

Fix: 6.1.22+
Fix from $1,950 2019-11-06
Debian Linux MEDIUM 6.1
CVE-2009-5046

JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

Fix: 6.1.22+
Fix from $1,600 2019-11-06
Debian Linux MEDIUM 6.1
CVE-2009-5049

WebApp JSP Snoop page XSS in jetty though 6.1.21.

Fix: after 6.1.21
Fix from $1,600 2019-11-06
Debian Linux HIGH 7.5
CVE-2011-4625

simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge…

Fix: 1.6.3 / 1.8.2+
Fix from $1,950 2019-11-06
Debian Linux CRITICAL 9.8
CVE-2007-0899

There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

Fix: 0.100.0+
Fix from $2,300 2019-11-06
Debian Linux HIGH 8.1
CVE-2006-4245

archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.

Patch available
Fix from $1,950 2019-11-06
Debian Linux MEDIUM 6.5
CVE-2013-6275

Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

Fix: after 5.1.2
Fix from $1,600 2019-11-05
Debian Linux MEDIUM 6.5
CVE-2013-6460

Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents

Fix: 1.5.11 / 1.6.1+
Fix from $1,600 2019-11-05
Debian Linux MEDIUM 6.5
CVE-2013-6461

Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits

Fix: 1.5.11 / 1.6.1+
Fix from $1,600 2019-11-05
Debian Linux HIGH 8.8
CVE-2013-6364

Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

No fix yet
Fix from $1,950 2019-11-05
Debian Linux MEDIUM 5.3
CVE-2013-6365

Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions

Patch available
Fix from $1,600 2019-11-05
Shadow HIGH 7.8
CVE-2005-4890

There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to…

Fix: after 4.1.5
Fix from $1,950 2019-11-04
Debian Linux HIGH 7.5
CVE-2013-4412

slim has NULL pointer dereference when using crypt() method from glibc 2.17

Fix: 1.3.6+
Fix from $1,950 2019-11-04
Debian Linux MEDIUM 6.1
CVE-2013-4168

Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.

Patch available
Fix from $1,600 2019-11-01
Debian Linux MEDIUM 5.5
CVE-2005-2351

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

Fix: after 1.5.20
Fix from $1,600 2019-11-01
Debian Linux HIGH 7.5
CVE-2013-2227EPSS 13%

GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

No fix yet
Fix from $1,950 2019-11-01
Debian Linux CRITICAL 9.8
CVE-2013-2739

MiniDLNA has heap-based buffer overflow

Fix: 1.1.0+
Fix from $2,300 2019-11-01
Debian Linux MEDIUM 5.5
CVE-2013-3718

evince is missing a check on number of pages which can lead to a segmentation fault

Patch available
Fix from $1,600 2019-11-01
Debian Linux HIGH 7.5
CVE-2013-2600

MiniUPnPd has information disclosure use of snprintf()

No fix yet
Fix from $1,950 2019-11-01
Debian Linux MEDIUM 6.5
CVE-2012-6123

Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."

Fix: 4.8.0+
Fix from $1,600 2019-10-31
Debian Linux HIGH 8.8
CVE-2013-2024

OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.

Fix: after 4.8.2
Fix from $1,950 2019-10-31