Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2007-6745
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.
Debian Linux
Mitigation only
HIGH 7.5
CVE-2013-1809
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure tempo…
Debian Linux
3.4.0+
HIGH 7.5
CVE-2007-5743
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
Debian Linux
No fix yet
MEDIUM 6.3
CVE-2013-1429
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
Lintian
2.5.10.5+
HIGH 7.5
CVE-2010-2450
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed …
Debian Linux
Patch available
MEDIUM 5.5
CVE-2013-1425
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
Debian Linux
1.0.4+
HIGH 8.8
CVE-2019-3465
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatur…
Debian Linux
after 3.0.3
HIGH 7.4
CVE-2012-0051
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.
Debian Linux
No fix yet
HIGH 7.5
CVE-2019-18804
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
Debian Linux
No fix yet
HIGH 7.5
CVE-2009-5045
Dump Servlet information leak in jetty before 6.1.22.
Debian Linux
6.1.22+
MEDIUM 6.1
CVE-2009-5046
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
Debian Linux
6.1.22+
MEDIUM 6.1
CVE-2009-5049
WebApp JSP Snoop page XSS in jetty though 6.1.21.
Debian Linux
after 6.1.21
HIGH 7.5
CVE-2011-4625
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge…
Debian Linux
1.6.3 / 1.8.2+
CRITICAL 9.8
CVE-2007-0899
There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
Debian Linux
0.100.0+
HIGH 8.1
CVE-2006-4245
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
Debian Linux
Patch available
MEDIUM 6.5
CVE-2013-6275
Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
Debian Linux
after 5.1.2
MEDIUM 6.5
CVE-2013-6460
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
Debian Linux
1.5.11 / 1.6.1+
MEDIUM 6.5
CVE-2013-6461
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
Debian Linux
1.5.11 / 1.6.1+
HIGH 8.8
CVE-2013-6364
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
Debian Linux
No fix yet
MEDIUM 5.3
CVE-2013-6365
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
Debian Linux
Patch available
HIGH 7.8
CVE-2005-4890
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to…
Shadow
after 4.1.5
HIGH 7.5
CVE-2013-4412
slim has NULL pointer dereference when using crypt() method from glibc 2.17
Debian Linux
1.3.6+
MEDIUM 6.1
CVE-2013-4168
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
Debian Linux
Patch available
MEDIUM 5.5
CVE-2005-2351
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
Debian Linux
after 1.5.20
HIGH 7.5
CVE-2013-2227EPSS 13%
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
Debian Linux
No fix yet
CRITICAL 9.8
CVE-2013-2739
MiniDLNA has heap-based buffer overflow
Debian Linux
1.1.0+
MEDIUM 5.5
CVE-2013-3718
evince is missing a check on number of pages which can lead to a segmentation fault
Debian Linux
Patch available
HIGH 7.5
CVE-2013-2600
MiniUPnPd has information disclosure use of snprintf()
Debian Linux
No fix yet
MEDIUM 6.5
CVE-2012-6123
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."
Debian Linux
4.8.0+
HIGH 8.8
CVE-2013-2024
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
Debian Linux
after 4.8.2