VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2010-3440MedNov 12, 2019
    risk 0.36cvss 5.5epss 0.00

    babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.

  • CVE-2005-2351MedNov 1, 2019
    risk 0.36cvss 5.5epss 0.00

    Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

  • CVE-2013-3718MedNov 1, 2019
    risk 0.36cvss 5.5epss 0.01

    evince is missing a check on number of pages which can lead to a segmentation fault

  • CVE-2010-3373MedOct 29, 2019
    risk 0.36cvss 5.5epss 0.00

    paxtest handles temporary files insecurely

  • CVE-2019-17349MedOct 8, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a LoadExcl or StoreExcl operation.

  • CVE-2019-17350MedOct 8, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Xen through 4.12.x allowing Arm domU attackers to cause a denial of service (infinite loop) involving a compare-and-exchange operation.

  • CVE-2019-15902MedSep 4, 2019
    risk 0.36cvss 5.6epss 0.01

    A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()"…

  • CVE-2019-14534MedAug 29, 2019
    risk 0.36cvss 5.5epss 0.01

    In VideoLAN VLC media player 3.0.7.1, there is a NULL pointer dereference at the function SeekPercent of demux/asf/asf.c that will lead to a denial of service attack.

  • CVE-2019-15145MedAug 18, 2019
    risk 0.36cvss 5.5epss 0.02

    DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in…

  • CVE-2019-15144MedAug 18, 2019
    risk 0.36cvss 5.5epss 0.02

    In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.

  • CVE-2019-15143MedAug 18, 2019
    risk 0.36cvss 5.5epss 0.02

    In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.

  • CVE-2019-15142MedAug 18, 2019
    risk 0.36cvss 5.5epss 0.02

    In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.

  • CVE-2019-14464MedJul 31, 2019
    risk 0.36cvss 5.5epss 0.01

    XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.

  • CVE-2019-14275MedJul 26, 2019
    risk 0.36cvss 5.5epss 0.01

    Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.

  • CVE-2019-1010069MedJul 18, 2019
    risk 0.36cvss 5.5epss 0.01

    moinejf abcm2ps 8.13.20 is affected by: Incorrect Access Control. The impact is: Allows attackers to cause a denial of service attack via a crafted file. The component is: front.c, function txt_add. The fixed version is: after commit commit 08aef597656d065e86075f3d53fda89765845ea…

  • CVE-2019-1010302MedJul 15, 2019
    risk 0.36cvss 5.5epss 0.01

    jhead 3.03 is affected by: Incorrect Access Control. The impact is: Denial of service. The component is: iptc.c Line 122 show_IPTC(). The attack vector is: the victim must open a specially crafted JPEG file.

  • CVE-2019-1010301MedJul 15, 2019
    risk 0.36cvss 5.5epss 0.01

    jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.

  • CVE-2019-12976MedJun 26, 2019
    risk 0.36cvss 5.5epss 0.02

    ImageMagick 7.0.8-34 has a memory leak in the ReadPCLImage function in coders/pcl.c.

  • CVE-2019-12975MedJun 26, 2019
    risk 0.36cvss 5.5epss 0.02

    ImageMagick 7.0.8-34 has a memory leak vulnerability in the WriteDPXImage function in coders/dpx.c.

  • CVE-2019-0196MedJun 11, 2019
    risk 0.36cvss 5.3epss 0.20

    A vulnerability was found in Apache HTTP Server 2.4.17 to 2.4.38. Using fuzzed network input, the http/2 request handling could be made to access freed memory in string comparison when determining the method of a request and thus process the request incorrectly.

  • CVE-2019-0220MedJun 11, 2019
    risk 0.36cvss 5.3epss 0.18

    A vulnerability was found in Apache HTTP Server 2.4.0 to 2.4.38. When the path component of a request URL contains multiple consecutive slashes ('/'), directives such as LocationMatch and RewriteRule must account for duplicates in regular expressions while other aspects of the…

  • CVE-2019-2101MedJun 7, 2019
    risk 0.36cvss 5.5epss 0.00

    In uvc_parse_standard_control of uvc_driver.c, there is a possible out-of-bound read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2019-12481MedMay 30, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function GetESD at isomedia/track.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2019-3882MedApr 24, 2019
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a…

  • CVE-2019-11459MedApr 22, 2019
    risk 0.36cvss 5.5epss 0.01

    The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.

  • CVE-2019-1788MedApr 8, 2019
    risk 0.36cvss 5.5epss 0.02

    A vulnerability in the Object Linking & Embedding (OLE2) file scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is…

  • CVE-2019-1787MedApr 8, 2019
    risk 0.36cvss 5.5epss 0.02

    A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is…

  • CVE-2019-10649MedMar 30, 2019
    risk 0.36cvss 5.5epss 0.02

    In ImageMagick 7.0.8-36 Q16, there is a memory leak in the function SVGKeyValuePairs of coders/svg.c, which allows an attacker to cause a denial of service via a crafted image file.

  • CVE-2019-3838MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.03

    It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

  • CVE-2019-3835MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.03

    It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

  • CVE-2019-10018MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.

  • CVE-2019-6454MedMar 21, 2019
    risk 0.36cvss 5.5epss 0.02

    An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a…

  • CVE-2019-9735MedMar 13, 2019
    risk 0.36cvss 6.5epss 0.04

    An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example,…

  • CVE-2019-9706MedMar 12, 2019
    risk 0.36cvss 5.5epss 0.00

    Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error.

  • CVE-2019-9705MedMar 12, 2019
    risk 0.36cvss 5.5epss 0.00

    Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.

  • CVE-2019-9704MedMar 12, 2019
    risk 0.36cvss 5.5epss 0.00

    Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.

  • CVE-2019-9209MedFeb 28, 2019
    risk 0.36cvss 5.5epss 0.01

    In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.

  • CVE-2019-5765MedFeb 19, 2019
    risk 0.36cvss 5.5epss 0.01

    An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.

  • CVE-2019-7665MedFeb 9, 2019
    risk 0.36cvss 5.5epss 0.01

    In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file…

  • CVE-2019-7663MedFeb 9, 2019
    risk 0.36cvss 6.5epss 0.03

    An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a…

  • CVE-2018-17189MedJan 30, 2019
    risk 0.36cvss 5.3epss 0.20

    In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.

  • CVE-2019-7150MedJan 29, 2019
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash,…

  • CVE-2018-4181MedJan 11, 2019
    risk 0.36cvss 5.5epss 0.00

    In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

  • CVE-2018-6147MedJan 9, 2019
    risk 0.36cvss 5.5epss 0.00

    Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.

  • CVE-2019-5719MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.01

    In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the ISAKMP dissector could crash. This was addressed in epan/dissectors/packet-isakmp.c by properly handling the case of a missing decryption data block.

  • CVE-2019-5718MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.01

    In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the RTSE dissector and other ASN.1 dissectors could crash. This was addressed in epan/charsets.c by adding a get_t61_string length check.

  • CVE-2019-5717MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.01

    In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting the invalid sequence number of zero.

  • CVE-2019-5716MedJan 8, 2019
    risk 0.36cvss 5.5epss 0.01

    In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB before its creation.

  • CVE-2018-19478MedJan 2, 2019
    risk 0.36cvss 5.5epss 0.02

    In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.

  • CVE-2018-20360MedDec 22, 2018
    risk 0.36cvss 5.5epss 0.01

    An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

Page 129 of 210