VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2020-13632MedMay 27, 2020
    risk 0.36cvss 5.5epss 0.01

    ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.

  • CVE-2020-13253MedMay 27, 2020
    risk 0.36cvss 5.5epss 0.00

    sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.

  • CVE-2020-3812MedMay 26, 2020
    risk 0.36cvss 5.5epss 0.00

    qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's…

  • CVE-2020-13434MedMay 24, 2020
    risk 0.36cvss 5.5epss 0.01

    SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

  • CVE-2020-12771MedMay 9, 2020
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in the Linux kernel through 5.6.11. btree_gc_coalesce in drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails.

  • CVE-2020-12767MedMay 9, 2020
    risk 0.36cvss 5.5epss 0.01

    exif_entry_get_value in exif-entry.c in libexif 0.6.21 has a divide-by-zero error.

  • CVE-2020-11765MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.

  • CVE-2020-11764MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.

  • CVE-2020-11763MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.

  • CVE-2020-11762MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.

  • CVE-2020-11761MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonstrated by FastHufDecoder::refill in ImfFastHuf.cpp.

  • CVE-2020-11760MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

  • CVE-2020-11759MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock, an attacker can write to an out-of-bounds pointer.

  • CVE-2020-11758MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h.

  • CVE-2020-11740MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests.…

  • CVE-2020-1951MedMar 23, 2020
    risk 0.36cvss 5.5epss 0.03

    A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.

  • CVE-2020-1950MedMar 23, 2020
    risk 0.36cvss 5.5epss 0.03

    A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.

  • CVE-2019-20503MedMar 6, 2020
    risk 0.36cvss 6.5epss 0.03

    usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.

  • CVE-2020-10029MedMar 4, 2020
    risk 0.36cvss 5.5epss 0.01

    The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is…

  • CVE-2020-7063MedFeb 27, 2020
    risk 0.36cvss 5.5epss 0.02

    In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when creating PHAR archive using PharData::buildFromIterator() function, the files are added with default permissions (0666, or all access) even if the original files on the filesystem were with more…

  • CVE-2012-0844MedFeb 21, 2020
    risk 0.36cvss 5.5epss 0.00

    Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar.

  • CVE-2020-0549MedJan 28, 2020
    risk 0.36cvss 5.5epss 0.01

    Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-8003MedJan 27, 2020
    risk 0.36cvss 5.5epss 0.00

    A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture allocation failure, because vrend_renderer_resource_allocated_texture is not an appropriate place for a free.

  • CVE-2020-8002MedJan 27, 2020
    risk 0.36cvss 5.5epss 0.00

    A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service via commands that attempt to launch a grid without previously providing a Compute Shader (CS).

  • CVE-2020-5202MedJan 21, 2020
    risk 0.36cvss 5.5epss 0.00

    apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port 3142, even if the explicit…

  • CVE-2019-20171MedDec 31, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metx_New in isomedia/box_code_base.c and abst_Read in isomedia/box_code_adobe.c.

  • CVE-2019-20170MedDec 31, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is an invalid pointer dereference in the function GF_IPMPX_AUTH_Delete() in odf/ipmpx_code.c.

  • CVE-2019-20165MedDec 31, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function ilst_item_Read() in isomedia/box_code_apple.c.

  • CVE-2019-20163MedDec 31, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is a NULL pointer dereference in the function gf_odf_avc_cfg_write_bs() in odf/descriptors.c.

  • CVE-2019-20162MedDec 31, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function gf_isom_box_parse_ex() in isomedia/box_funcs.c.

  • CVE-2019-20161MedDec 31, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in GPAC version 0.8.0 and 0.9.0-development-20191109. There is heap-based buffer overflow in the function ReadGF_IPMPX_WatermarkingInit() in odf/ipmpx_code.c.

  • CVE-2012-5476MedDec 30, 2019
    risk 0.36cvss 5.5epss 0.00

    Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.

  • CVE-2012-5474MedDec 30, 2019
    risk 0.36cvss 5.5epss 0.00

    The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

  • CVE-2019-19813MedDec 17, 2019
    risk 0.36cvss 5.5epss 0.02

    In the Linux kernel 5.0.21, mounting a crafted btrfs filesystem image, performing some operations, and then making a syncfs system call can lead to a use-after-free in __mutex_lock in kernel/locking/mutex.c. This is related to mutex_can_spin_on_owner in kernel/locking/mutex.c,…

  • CVE-2019-19797MedDec 15, 2019
    risk 0.36cvss 5.5epss 0.01

    read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.

  • CVE-2013-4184MedDec 10, 2019
    risk 0.36cvss 5.5epss 0.01

    Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks

  • CVE-2019-1551MedDec 6, 2019
    risk 0.36cvss 5.3epss 0.14

    There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult…

  • CVE-2012-1105MedDec 5, 2019
    risk 0.36cvss 5.5epss 0.00

    An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner.

  • CVE-2013-0326MedDec 5, 2019
    risk 0.36cvss 5.5epss 0.00

    OpenStack nova base images permissions are world readable

  • CVE-2019-19462MedNov 30, 2019
    risk 0.36cvss 5.5epss 0.00

    relay_open in kernel/relay.c in the Linux kernel through 5.4.1 allows local users to cause a denial of service (such as relay blockage) by triggering a NULL alloc_percpu result.

  • CVE-2012-5644MedNov 25, 2019
    risk 0.36cvss 5.5epss 0.00

    libuser has information disclosure when moving user's home directory

  • CVE-2019-18890MedNov 21, 2019
    risk 0.36cvss 6.5epss 0.04

    A SQL injection vulnerability in Redmine through 3.2.9 and 3.3.x before 3.3.10 allows Redmine users to access protected information via a crafted object query.

  • CVE-2019-19039MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.01

    __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS development team…

  • CVE-2015-1606MedNov 20, 2019
    risk 0.36cvss 5.5epss 0.02

    The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file.

  • CVE-2012-6136MedNov 20, 2019
    risk 0.36cvss 5.5epss 0.00

    tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

  • CVE-2011-2924MedNov 19, 2019
    risk 0.36cvss 5.5epss 0.00

    foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…

  • CVE-2011-2923MedNov 19, 2019
    risk 0.36cvss 5.5epss 0.00

    foomatic-rip filter, all versions, used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible…

  • CVE-2012-0843MedNov 19, 2019
    risk 0.36cvss 5.5epss 0.00

    uzbl: Information disclosure via world-readable cookies storage file

  • CVE-2012-0842MedNov 19, 2019
    risk 0.36cvss 5.5epss 0.00

    surf: cookie jar has read access from other local user

  • CVE-2010-4817MedNov 13, 2019
    risk 0.36cvss 5.5epss 0.00

    pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.

Page 128 of 210