Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2012-1114 A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_… Debian Linux Mitigation only Fix from $1,6002019-12-05 MEDIUM 6.1 CVE-2012-1115 A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php. Debian Linux Mitigation only Fix from $1,6002019-12-05 MEDIUM 5.3 CVE-2012-1104 A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed. Debian Linux No fix yet Fix from $1,6002019-12-05 MEDIUM 5.5 CVE-2013-0326 OpenStack nova base images permissions are world readable Debian Linux Mitigation only Fix from $1,6002019-12-05 CRITICAL 9.8 CVE-2013-2745 An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0 Debian Linux 1.1.0+ Fix from $2,3002019-12-04 HIGH 8.8 CVE-2013-7325 An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball. Devscripts 2.13.19+ Fix from $1,9502019-12-03 MEDIUM 5.3 CVE-2015-7542 A vulnerability exists in libgwenhywfar through 4.12.0 due to the usage of outdated bundled CA certificates. Debian Linux after 4.12.0 Fix from $1,6002019-12-03 HIGH 7.5 CVE-2013-2106 webauth before 4.6.1 has authentication credential disclosure Debian Linux 4.6.1+ Fix from $1,9502019-12-03 HIGH 7.5 CVE-2012-4428EPSS 10% openslp: SLPIntersectStringList()' Function has a DoS vulnerability Debian Linux Mitigation only Fix from $1,9502019-12-02 MEDIUM 5.5 CVE-2019-19479 An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsin… Debian Linux after 0.19.0 Fix from $1,6002019-12-01 MEDIUM 5.9 CVE-2015-0837 The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differe… Debian Linux 1.4.19 / 1.6.3+ Fix from $1,6002019-11-29 CRITICAL 9.8 CVE-2011-2523EPSS 96% vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp. Debian Linux No fix yet Fix from $2,3002019-11-27 MEDIUM 5.3 CVE-2011-2515 PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and ex… Debian Linux Mitigation only Fix from $1,6002019-11-27 MEDIUM 6.5 CVE-2013-2625 An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1… Debian Linux 2.0.8 / 2.1.4+ Fix from $1,6002019-11-27 HIGH 8.1 CVE-2012-2248 An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable. Debian Linux Mitigation only Fix from $1,9502019-11-27 HIGH 7.8 CVE-2011-2187 xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows loc… Debian Linux 5.14+ Fix from $1,9502019-11-27 MEDIUM 6.5 CVE-2011-4350EPSS 16% Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain co… Debian Linux No fix yet Fix from $1,6002019-11-26 CRITICAL 9.8 CVE-2011-4120 Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured… Debian Linux 2.10+ Fix from $2,3002019-11-26 HIGH 7.5 CVE-2011-4082 A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remot… Debian Linux 0.9.8+ Fix from $1,9502019-11-26 HIGH 8.8 CVE-2011-3631 Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done i… Debian Linux 0.1.2+ Fix from $1,9502019-11-26 HIGH 7.1 CVE-2011-3632 Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks. Debian Linux 0.1.2+ Fix from $1,9502019-11-26 HIGH 8.8 CVE-2011-3630 Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are pr… Debian Linux 0.1.2+ Fix from $1,9502019-11-26 MEDIUM 6.5 CVE-2011-3617 Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases. Debian Linux after 1.8.2 Fix from $1,6002019-11-26 HIGH 7.5 CVE-2011-3596EPSS 11% Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request. Debian Linux 1.0.4.1+ Fix from $1,9502019-11-26 HIGH 7.5 CVE-2015-1396 A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a pa… Debian Linux 2.7.4+ Fix from $1,9502019-11-25 MEDIUM 5.5 CVE-2012-5644 libuser has information disclosure when moving user's home directory Debian Linux 0.59+ Fix from $1,6002019-11-25 MEDIUM 6.5 CVE-2012-5521 quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal Debian Linux Mitigation only Fix from $1,6002019-11-25 CRITICAL 9.8 CVE-2014-6310 Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function. Debian Linux Patch available Fix from $2,3002019-11-22 CRITICAL 9.8 CVE-2014-6311 generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges. Debian Linux after 6.2.6 Fix from $2,3002019-11-22 HIGH 8.8 CVE-2019-18610EPSS 30% An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenti… Debian Linux 13.29.2 / 16.6.2+ Fix from $1,9502019-11-22