Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2014-0021 Chrony before 1.29.1 has traffic amplification in cmdmon protocol Debian Linux 1.29+ Fix from $1,9502019-11-15 MEDIUM 5.9 CVE-2013-4584 Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_… Debian Linux 2.1+ Fix from $1,6002019-11-15 MEDIUM 6.5 CVE-2018-12207 Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to … Debian Linux after 15.0.1 Fix from $1,6002019-11-14 MEDIUM 6.0 CVE-2019-11139 Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentiall… Debian Linux Mitigation only Fix from $1,6002019-11-14 CRITICAL 9.8 CVE-2011-1930EPSS 21% In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker … Debian Linux 1.5.25+ Fix from $2,3002019-11-14 HIGH 7.8 CVE-2011-1145 The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE para… Debian Linux after 2.2.14 Fix from $1,9502019-11-14 HIGH 7.8 CVE-2011-1588 Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error. Debian Linux Patch available Fix from $1,9502019-11-14 MEDIUM 5.5 CVE-2011-1488 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local a… Debian Linux 5.7.6+ Fix from $1,6002019-11-14 MEDIUM 5.5 CVE-2011-1489 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages were logged when multiple rulesets were used and some output… Debian Linux 5.7.6+ Fix from $1,6002019-11-14 MEDIUM 5.5 CVE-2011-1490 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output … Debian Linux 5.7.6+ Fix from $1,6002019-11-14 HIGH 7.8 CVE-2011-1070 v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mod… Debian Linux 0.1.10+ Fix from $1,9502019-11-14 MEDIUM 6.1 CVE-2011-0544 phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag. Debian Linux after 3.0.6 Fix from $1,6002019-11-14 HIGH 7.5 CVE-2010-5108 Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and res… Debian Linux Mitigation only Fix from $1,9502019-11-13 HIGH 8.8 CVE-2010-4664 In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their… Debian Linux 0.4.2+ Fix from $1,9502019-11-13 MEDIUM 5.5 CVE-2010-4817 pithos before 0.3.5 allows overwrite of arbitrary files via symlinks. Debian Linux 0.3.5+ Fix from $1,6002019-11-13 HIGH 7.8 CVE-2010-4661 udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. Debian Linux 1.0.3+ Fix from $1,9502019-11-13 HIGH 7.8 CVE-2010-4654 poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. Debian Linux 0.16.3+ Fix from $1,9502019-11-13 MEDIUM 6.5 CVE-2010-4653 An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts. Debian Linux 0.16.3+ Fix from $1,6002019-11-13 CRITICAL 9.8 CVE-2010-4533 offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed proto… Debian Linux 6.3.4+ Fix from $2,3002019-11-13 MEDIUM 5.9 CVE-2010-4532 offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle … Debian Linux 6.3.2+ Fix from $1,6002019-11-13 MEDIUM 6.5 CVE-2012-4385 letodms 3.3.6 has CSRF via change password Debian Linux No fix yet Fix from $1,6002019-11-13 MEDIUM 6.1 CVE-2012-4384 letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar Debian Linux after 3.3.11 Fix from $1,6002019-11-13 HIGH 7.8 CVE-2019-18397 A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to caus… Debian Linux after 1.0.7 Fix from $1,9502019-11-13 HIGH 8.8 CVE-2010-3844 An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack. Debian Linux Patch available Fix from $1,9502019-11-12 MEDIUM 5.5 CVE-2010-3440 babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker… Debian Linux 2.0.11+ Fix from $1,6002019-11-12 CRITICAL 9.8 CVE-2010-3438 libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing… Debian Linux 6.32+ Fix from $2,3002019-11-12 MEDIUM 6.5 CVE-2010-3439 It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download co… Debian Linux No fix yet Fix from $1,6002019-11-12 HIGH 7.5 CVE-2012-1572 OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space Debian Linux Patch available Fix from $1,9502019-11-12 HIGH 7.8 CVE-2011-3618 atop: symlink attack possible due to insecure tempfile handling Debian Linux Patch available Fix from $1,9502019-11-12 CRITICAL 9.8 CVE-2008-7291 gri before 2.12.18 generates temporary files in an insecure way. Debian Linux 2.12.18+ Fix from $2,3002019-11-08