Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2008-1673EPSS 7%
The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (…
Debian Linux
Patch available
HIGH 7.2
CVE-2008-1901
aptlinex before 0.91 allows local users to overwrite arbitrary files via a symlink attack on the gambas-apt.lock temporary file.
Aptlinex
Mitigation only
MEDIUM 5.0
CVE-2008-1902
The GUI for aptlinex before 0.91 does not sufficiently warn the user of potentially dangerous actions, which allows remote attackers to remove or mod…
Aptlinex
Mitigation only
MEDIUM 5.5
CVE-2008-1567
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp…
Debian Linux
2.11.5.1+
CRITICAL 9.8
CVE-2008-0062EPSS 10%
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of servic…
Debian Linux
after 1.6.3
HIGH 7.2
CVE-2008-0302
Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious…
Apt Listchanges
after 2.81
MEDIUM 5.0
CVE-2007-6284
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containi…
Debian Linux
Patch available
HIGH 10.0
CVE-2007-6610
unp 1.0.12, and other versions before 1.0.14, does not properly escape file names, which might allow context-dependent attackers to execute arbitrary…
Unp
after 1.0.12
HIGH 7.5
CVE-2007-6353
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a he…
Debian Linux
0.16+
MEDIUM 6.5
CVE-2007-6170
SQL injection vulnerability in the Call Detail Record Postgres logging engine (cdr_pgsql) in Asterisk 1.4.x before 1.4.15, 1.2.x before 1.2.25, B.x b…
Debian Linux
1.2.25 / 1.4.15+
HIGH 7.2
CVE-2007-5729
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_…
Debian Linux
Mitigation only
HIGH 7.2
CVE-2007-5730
Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data i…
Debian Linux
Mitigation only
HIGH 7.2
CVE-2007-5365EPSS 80%
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based…
Debian Linux
Patch available
HIGH 7.2
CVE-2007-3912
checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a ru…
Debian Goodies
Patch available
MEDIUM 5.0
CVE-2007-4739
reprepro 1.3.0 through 2.2.3 does not properly verify signatures when updating repositories, which allows remote attackers to construct and distribut…
Reprepro
Patch available
HIGH 7.5
CVE-2007-4476EPSS 15%
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
Debian Linux
1.19+
MEDIUM 6.8
CVE-2007-3387EPSS 9%
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf…
Debian Linux
0.5.91 / 2.8.2+
HIGH 7.2
CVE-2007-2839
gfax 0.4.2 and probably other versions creates temporary files insecurely, which allows local users to execute arbitrary commands via unknown vectors.
Gfax
after 0.4.2
HIGH 10.0
CVE-2007-2442EPSS 11%
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary c…
Debian Linux
after 1.6.1
HIGH 8.3
CVE-2007-2443
Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might …
Debian Linux
after 1.6.1
HIGH 7.5
CVE-2007-3409
Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet w…
Debian Linux
0.60+
HIGH 7.8
CVE-2007-2833
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, …
Debian Linux
Mitigation only
HIGH 7.2
CVE-2007-2444
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and…
Debian Linux
Patch available
HIGH 10.0
CVE-2007-0956EPSS 30%
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning…
Debian Linux
1.6.1+
HIGH 9.0
CVE-2007-0957EPSS 10%
Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Di…
Debian Linux
1.6.1+
HIGH 9.3
CVE-2007-1667
Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagi…
Debian Linux
after 1.0.2
MEDIUM 6.6
CVE-2006-7098
The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when http…
Apache
Mitigation only
HIGH 7.5
CVE-2007-0897
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of s…
Debian Linux
0.90 / 10.4.11+
HIGH 7.5
CVE-2007-0454EPSS 6%
Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code v…
Debian Linux
Patch available
MEDIUM 6.8
CVE-2006-6942
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyAdmin before 2.9.1.1 allow remote attackers to inject arbitrary HTML or web script via (1…
Debian Linux
after 2.9.1