VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2012-2248HigNov 27, 2019
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable.

  • CVE-2019-16255HigNov 26, 2019
    risk 0.53cvss 8.1epss 0.04

    Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.

  • CVE-2011-3596HigNov 26, 2019
    risk 0.53cvss 7.5epss 0.11

    Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.

  • CVE-2019-18610HigNov 22, 2019
    risk 0.53cvss 8.8epss 0.30

    An issue was discovered in manager.c in Sangoma Asterisk through 13.x, 16.x, 17.x and Certified Asterisk 13.21 through 13.21-cert4. A remote authenticated Asterisk Manager Interface (AMI) user without system authorization could use a specially crafted Originate AMI request to…

  • CVE-2006-4245HigNov 6, 2019
    risk 0.53cvss 8.1epss 0.01

    archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.

  • CVE-2013-6364HigNov 5, 2019
    risk 0.53cvss 8.8epss 0.02

    Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

  • CVE-2005-2352HigNov 1, 2019
    risk 0.53cvss 8.1epss 0.01

    I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.

  • CVE-2013-2227HigNov 1, 2019
    risk 0.53cvss 7.5epss 0.13

    GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

  • CVE-2011-1408HigOct 29, 2019
    risk 0.53cvss 8.2epss 0.02

    ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.

  • CVE-2019-9506HigAug 14, 2019
    risk 0.53cvss 8.1epss 0.03

    The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and…

  • CVE-2019-9511HigAug 13, 2019
    risk 0.53cvss 7.5epss 0.60

    Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size…

  • CVE-2019-13616HigJul 16, 2019
    risk 0.53cvss 8.1epss 0.04

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.

  • CVE-2019-13031HigJun 28, 2019
    risk 0.53cvss 8.1epss 0.02

    LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notification server is not enabled and has a "deny all" rule.

  • CVE-2019-9499HigApr 17, 2019
    risk 0.53cvss 8.1epss 0.02

    The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of…

  • CVE-2019-9498HigApr 17, 2019
    risk 0.53cvss 8.1epss 0.02

    The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete…

  • CVE-2019-11009HigApr 8, 2019
    risk 0.53cvss 8.1epss 0.02

    In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows attackers to cause a denial of service or information disclosure via a crafted image file.

  • CVE-2019-11007HigApr 8, 2019
    risk 0.53cvss 8.1epss 0.02

    In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.

  • CVE-2019-10650HigMar 30, 2019
    risk 0.53cvss 8.1epss 0.04

    In ImageMagick 7.0.8-36 Q16, there is a heap-based buffer over-read in the function WriteTIFFImage of coders/tiff.c, which allows an attacker to cause a denial of service or information disclosure via a crafted image file.

  • CVE-2019-5755HigFeb 19, 2019
    risk 0.53cvss 8.1epss 0.02

    Incorrect handling of negative zero in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.

  • CVE-2019-7659HigFeb 9, 2019
    risk 0.53cvss 8.1epss 0.02

    Genivia gSOAP 2.7.x and 2.8.x before 2.8.75 allows attackers to cause a denial of service (application abort) or possibly have unspecified other impact if a server application is built with the -DWITH_COOKIES flag. This affects the C/C++ libgsoapck/libgsoapck++ and…

  • CVE-2019-7636HigFeb 8, 2019
    risk 0.53cvss 8.1epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDL_GetRGB in video/SDL_pixels.c.

  • CVE-2019-7635HigFeb 8, 2019
    risk 0.53cvss 8.1epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.

  • CVE-2019-7578HigFeb 7, 2019
    risk 0.53cvss 8.1epss 0.03

    SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitIMA_ADPCM in audio/SDL_wave.c.

  • CVE-2018-5740HigJan 16, 2019
    risk 0.53cvss 7.5epss 0.60

    "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the…

  • CVE-2018-20547HigDec 28, 2018
    risk 0.53cvss 8.1epss 0.02

    There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data.

  • CVE-2018-16874HigDec 14, 2018
    risk 0.53cvss 8.1epss 0.05

    In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but…

  • CVE-2018-19662HigNov 29, 2018
    risk 0.53cvss 8.1epss 0.02

    An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service.

  • CVE-2018-19627HigNov 29, 2018
    risk 0.53cvss 7.5epss 0.18

    In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.

  • CVE-2018-16396HigNov 16, 2018
    risk 0.53cvss 8.1epss 0.08

    An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

  • CVE-2018-16843HigNov 7, 2018
    risk 0.53cvss 7.5epss 0.47

    nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is…

  • CVE-2018-6034HigSep 25, 2018
    risk 0.53cvss 8.1epss 0.02

    Insufficient data validation in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2018-17281HigSep 24, 2018
    risk 0.53cvss 7.5epss 0.53

    There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk through 13.23.0, 14.7.x through 14.7.7, and 15.x through 15.6.0 and Certified Asterisk through 13.21-cert2. It allows an attacker to crash Asterisk via a specially crafted HTTP request to…

  • CVE-2018-10927HigSep 4, 2018
    risk 0.53cvss 8.1epss 0.03

    A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.

  • CVE-2018-10923HigSep 4, 2018
    risk 0.53cvss 8.1epss 0.02

    It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.

  • CVE-2018-14348HigAug 14, 2018
    risk 0.53cvss 8.1epss 0.02

    libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.

  • CVE-2018-10925HigAug 9, 2018
    risk 0.53cvss 8.1epss 0.02

    It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read…

  • CVE-2017-15120HigJul 27, 2018
    risk 0.53cvss 7.5epss 0.52

    An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL pointer dereference when parsing a specially crafted answer containing a CNAME of a different class than IN. An unauthenticated remote attacker could cause a…

  • CVE-2018-11806HigJun 13, 2018
    risk 0.53cvss 8.2epss 0.01

    m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.

  • CVE-2018-0732HigJun 12, 2018
    risk 0.53cvss 7.5epss 0.49

    During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the…

  • CVE-2018-5178HigJun 11, 2018
    risk 0.53cvss 8.1epss 0.05

    A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8,…

  • CVE-2017-7807HigJun 11, 2018
    risk 0.53cvss 8.1epss 0.02

    A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3,…

  • CVE-2018-1000301CriMay 24, 2018
    risk 0.53cvss 9.1epss 0.06

    curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability…

  • CVE-2017-2835HigApr 24, 2018
    risk 0.53cvss 8.1epss 0.01

    An exploitable code execution vulnerability exists in the RDP receive functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server response can cause an out-of-bounds write resulting in an exploitable condition. An attacker can compromise the server or use a man in…

  • CVE-2018-1088HigApr 18, 2018
    risk 0.53cvss 8.1epss 0.06

    A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.

  • CVE-2017-2619HigMar 12, 2018
    risk 0.53cvss 7.5epss 0.11

    Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition.

  • CVE-2017-8823HigDec 3, 2017
    risk 0.53cvss 8.1epss 0.02

    In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, there is a use-after-free in onion service v2 during intro-point expiration because the expiring list is mismanaged in certain error cases, aka…

  • CVE-2017-17085HigDec 1, 2017
    risk 0.53cvss 7.5epss 0.17

    In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissectors/packet-cipsafety.c by validating the packet length.

  • CVE-2017-15098HigNov 22, 2017
    risk 0.53cvss 8.1epss 0.04

    Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.

  • CVE-2017-16853HigNov 16, 2017
    risk 0.53cvss 8.1epss 0.01

    The DynamicMetadataProvider class in saml/saml2/metadata/impl/DynamicMetadataProvider.cpp in OpenSAML-C in OpenSAML before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification,…

  • CVE-2017-16852HigNov 16, 2017
    risk 0.53cvss 8.1epss 0.01

    shibsp/metadata/DynamicMetadataProvider.cpp in the Dynamic MetadataProvider plugin in Shibboleth Service Provider before 2.6.1 fails to properly configure itself with the MetadataFilter plugins and does not perform critical security checks such as signature verification,…

Page 42 of 210