VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2023-2462MedMay 3, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-46877MedDec 22, 2022
    risk 0.28cvss 4.3epss 0.01

    By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108.

  • CVE-2022-39348MedOct 26, 2022
    risk 0.28cvss 5.4epss 0.01

    Twisted is an event-based framework for internet applications. Started with version 0.9.4, when the host header does not match a configured host `twisted.web.vhost.NameVirtualHost` will return a `NoResource` resource which renders the Host header unescaped into the 404 response…

  • CVE-2022-3435MedOct 8, 2022
    risk 0.28cvss 4.3epss 0.04

    A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It…

  • CVE-2022-38648MedSep 22, 2022
    risk 0.28cvss 5.3epss 0.02

    Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.

  • CVE-2018-25047MedSep 15, 2022
    risk 0.28cvss 5.4epss 0.01

    In Smarty before 3.1.47 and 4.x before 4.2.1, libs/plugins/function.mailto.php allows XSS. A web page that uses smarty_function_mailto, and that could be parameterized using GET or POST input parameters, could allow injection of JavaScript code by a user.

  • CVE-2022-2787MedAug 27, 2022
    risk 0.28cvss 4.3epss 0.01

    Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.

  • CVE-2021-28544MedApr 12, 2022
    risk 0.28cvss 4.3epss 0.03

    Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy…

  • CVE-2022-0585MedFeb 18, 2022
    risk 0.28cvss 4.3epss 0.02

    Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file

  • CVE-2021-38020MedDec 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-43546MedDec 8, 2021
    risk 0.28cvss 4.3epss 0.01

    It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

  • CVE-2021-43538MedDec 8, 2021
    risk 0.28cvss 4.3epss 0.01

    By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR <…

  • CVE-2021-38509MedDec 8, 2021
    risk 0.28cvss 4.3epss 0.02

    Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and…

  • CVE-2021-38508MedDec 8, 2021
    risk 0.28cvss 4.3epss 0.02

    By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability…

  • CVE-2021-38506MedDec 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

  • CVE-2021-38004MedNov 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-41229MedNov 12, 2021
    risk 0.28cvss 4.3epss 0.01

    BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can…

  • CVE-2021-42096MedOct 21, 2021
    risk 0.28cvss 4.3epss 0.01

    GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin password, and may be useful in conducting a brute-force attack against that password.

  • CVE-2021-37971MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-37968MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-37967MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

  • CVE-2021-37966MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-37965MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-37963MedOct 8, 2021
    risk 0.28cvss 4.3epss 0.01

    Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.

  • CVE-2021-39200MedSep 9, 2021
    risk 0.28cvss 5.3epss 0.02

    WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. In affected versions output data of the function wp_die() can be leaked under certain conditions, which can include data like nonces. It can then be used to…

  • CVE-2021-2369MedJul 21, 2021
    risk 0.28cvss 4.3epss 0.03

    Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Library). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Easily exploitable vulnerability…

  • CVE-2020-36425MedJul 19, 2021
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.

  • CVE-2020-36422MedJul 19, 2021
    risk 0.28cvss 5.3epss 0.01

    An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.

  • CVE-2020-36421MedJul 19, 2021
    risk 0.28cvss 5.3epss 0.02

    An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.

  • CVE-2021-21228MedApr 30, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

  • CVE-2021-30159MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.02

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget() uses FOR UPDATE, but it's only called if…

  • CVE-2021-30155MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.

  • CVE-2021-30152MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.01

    An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.

  • CVE-2020-36308MedApr 6, 2021
    risk 0.28cvss 5.3epss 0.01

    Redmine before 4.0.7 and 4.1.x before 4.1.1 allows attackers to discover the subject of a non-visible issue by performing a CSV export and reading time entries.

  • CVE-2021-20296MedApr 1, 2021
    risk 0.28cvss 5.3epss 0.02

    A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could cause a NULL pointer dereference. The highest threat from this vulnerability is to…

  • CVE-2021-21189MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-21187MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2021-21186MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code.

  • CVE-2021-21185MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension.

  • CVE-2021-21184MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-21183MedMar 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2021-23969MedFeb 26, 2021
    risk 0.28cvss 4.3epss 0.01

    As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid…

  • CVE-2021-23968MedFeb 26, 2021
    risk 0.28cvss 4.3epss 0.01

    If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability…

  • CVE-2020-0499MedDec 15, 2020
    risk 0.28cvss 4.3epss 0.04

    In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:…

  • CVE-2020-26421MedDec 11, 2020
    risk 0.28cvss 4.2epss 0.03

    Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.

  • CVE-2020-29130MedNov 26, 2020
    risk 0.28cvss 4.3epss 0.02

    slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

  • CVE-2020-29129MedNov 26, 2020
    risk 0.28cvss 4.3epss 0.01

    ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.

  • CVE-2020-28040MedNov 2, 2020
    risk 0.28cvss 4.3epss 0.01

    WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.

  • CVE-2020-26932MedOct 10, 2020
    risk 0.28cvss 4.3epss 0.01

    debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group)

  • CVE-2020-7070MedOct 2, 2020
    risk 0.28cvss 4.3epss 0.05

    In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading…

Page 150 of 210