Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2020-1765
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicketForward, AgentTicke…
Debian Linux
after 7.0.13
HIGH 7.8
CVE-2019-20373
LTSP LDM through 2.18.06 allows fat-client root access because the LDM_USERNAME variable may have an empty value if the user's shell lacks support fo…
Debian Linux
after 2.18.06
HIGH 8.8
CVE-2020-5504EPSS 39%
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of…
Debian Linux
4.9.4 / 5.0.1+
CRITICAL 9.1
CVE-2019-20367
nlist.c in libbsd before 0.10.0 has an out-of-bounds read during a comparison for a symbol name from the string table (strtab).
Debian Linux
0.10.0+
MEDIUM 5.5
CVE-2020-0009
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalati…
Debian Linux
Patch available
HIGH 7.5
CVE-2019-18625
An issue was discovered in Suricata 5.0.0. It was possible to bypass/evade any tcp based signature by faking a closed TCP session using an evil serve…
Debian Linux
Patch available
CRITICAL 9.1
CVE-2019-18792
An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet…
Debian Linux
4.1.6+
CRITICAL 9.8
CVE-2019-20330EPSS 9%
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
Debian Linux
2.7.9.7 / 2.8.11.5+
HIGH 7.5
CVE-2014-8182
An off-by-one error leading to a crash was discovered in openldap 2.4 when processing DNS SRV messages. If slapd was configured to use the dnssrv bac…
Debian Linux
Patch available
MEDIUM 5.9
CVE-2014-6275
FusionForge before 5.3.2 use scripts that run under the shared Apache user, which is also used by project homepages by default. If project webpages a…
Debian Linux
5.3.2+
MEDIUM 5.5
CVE-2019-20208
dimC_Read in isomedia/box_code_3gpp.c in GPAC from 0.5.2 to 0.8.0 has a stack-based buffer overflow.
Debian Linux
after 0.8.0
HIGH 7.5
CVE-2013-4357
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
Debian Linux
2.14+
MEDIUM 6.5
CVE-2019-14466
The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to per…
Debian Linux
Patch available
MEDIUM 5.5
CVE-2019-20170
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_D…
Debian Linux
No fix yet
MEDIUM 5.5
CVE-2019-20171
An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metx_New in isomedia/box_code_base.c and abst…
Debian Linux
after 0.8.0
MEDIUM 5.5
CVE-2019-20161
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_Waterm…
Debian Linux
No fix yet
MEDIUM 5.5
CVE-2019-20162
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_e…
Debian Linux
No fix yet
MEDIUM 5.5
CVE-2019-20163
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_writ…
Debian Linux
No fix yet
MEDIUM 5.5
CVE-2019-20165
An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in…
Debian Linux
No fix yet
HIGH 7.8
CVE-2013-2016
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the vi…
Debian Linux
after 1.4.2
MEDIUM 5.5
CVE-2012-5476
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the adm…
Debian Linux
Mitigation only
HIGH 8.2
CVE-2019-16789
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the fr…
Debian Linux
after 1.4.0
HIGH 7.5
CVE-2019-19956EPSS 6%
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
Debian Linux
2.9.10+
CRITICAL 9.8
CVE-2019-19950
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
Debian Linux
Patch available
CRITICAL 9.8
CVE-2019-19951
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
Debian Linux
Patch available
CRITICAL 9.1
CVE-2019-19949
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_pr…
Debian Linux
6.9.10-43 / 7.0.8-43+
CRITICAL 9.1
CVE-2019-19953
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
Debian Linux
Patch available
HIGH 7.8
CVE-2019-3467
Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive A…
Debian Lan Config
0.26 / 2.11.10+
MEDIUM 5.5
CVE-2019-18388
A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.0 allows guest OS users to cause a denial of service via malformed comman…
Debian Linux
after 0.8.0
HIGH 7.5
CVE-2019-16785
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fiel…
Debian Linux
after 1.3.1