VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2010-4661HigNov 13, 2019
    risk 0.51cvss 7.8epss 0.00

    udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

  • CVE-2010-4654HigNov 13, 2019
    risk 0.51cvss 7.8epss 0.01

    poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

  • CVE-2011-3618HigNov 12, 2019
    risk 0.51cvss 7.8epss 0.00

    atop: symlink attack possible due to insecure tempfile handling

  • CVE-2017-5333HigNov 4, 2019
    risk 0.51cvss 7.8epss 0.02

    Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.

  • CVE-2017-5332HigNov 4, 2019
    risk 0.51cvss 7.8epss 0.02

    The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

  • CVE-2017-5331HigNov 4, 2019
    risk 0.51cvss 7.8epss 0.00

    Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.

  • CVE-2010-0747HigOct 30, 2019
    risk 0.51cvss 7.8epss 0.00

    drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.

  • CVE-2019-17347HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges because a guest can manipulate its virtualised %cr4 in a way that is incompatible with Linux (and possibly other guest kernels).

  • CVE-2019-17341HigOct 8, 2019
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service or gain privileges by leveraging a page-writability race condition during addition of a passed-through PCI device.

  • CVE-2019-16729HigSep 24, 2019
    risk 0.51cvss 7.8epss 0.00

    pam-python before 1.0.7-1 has an issue in regard to the default environment variable handling of Python, which could allow for local root escalation in certain PAM setups.

  • CVE-2019-14835HigSep 17, 2019
    risk 0.51cvss 7.8epss 0.01

    A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to…

  • CVE-2019-14817HigSep 3, 2019
    risk 0.51cvss 7.8epss 0.02

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and…

  • CVE-2019-14811HigSep 3, 2019
    risk 0.51cvss 7.8epss 0.04

    A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and…

  • CVE-2019-14970HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a crafted .mkv file.

  • CVE-2019-14778HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    The mkv::virtual_segment_c::seek method of demux/mkv/virtual_segment.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

  • CVE-2019-14777HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    The Control function of demux/mkv/mkv.cpp in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

  • CVE-2019-14776HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    A heap-based buffer over-read exists in DemuxInit() in demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 via a crafted .mkv file.

  • CVE-2019-14533HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    The Control function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1 has a use-after-free.

  • CVE-2019-14535HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    A divide-by-zero error exists in the SeekIndex function of demux/asf/asf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted WMV file.

  • CVE-2019-14498HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    A divide-by-zero error exists in the Control function of demux/caf.c in VideoLAN VLC media player 3.0.7.1. As a result, an FPE can be triggered via a crafted CAF file.

  • CVE-2019-14438HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.02

    A heap-based buffer over-read in xiph_PackHeaders() in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer over-read via a crafted .ogg file.

  • CVE-2019-14437HigAug 29, 2019
    risk 0.51cvss 7.8epss 0.01

    The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file.

  • CVE-2019-9852HigAug 15, 2019
    risk 0.51cvss 7.8epss 0.02

    LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of…

  • CVE-2019-9518HigAug 13, 2019
    risk 0.51cvss 7.5epss 0.25

    Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE.…

  • CVE-2019-9517HigAug 13, 2019
    risk 0.51cvss 7.5epss 0.28

    Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually…

  • CVE-2019-14744HigAug 7, 2019
    risk 0.51cvss 7.8epss 0.04

    In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon…

  • CVE-2019-14497HigAug 1, 2019
    risk 0.51cvss 7.8epss 0.01

    ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker 1.02.00 has a heap-based buffer overflow.

  • CVE-2019-14496HigAug 1, 2019
    risk 0.51cvss 7.8epss 0.01

    LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker 1.02.00 has a stack-based buffer overflow.

  • CVE-2019-13638HigJul 26, 2019
    risk 0.51cvss 7.8epss 0.04

    GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to be present on the vulnerable system. This is different from…

  • CVE-2019-1010057HigJul 16, 2019
    risk 0.51cvss 7.8epss 0.02

    nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. The component is: nfx.c:546, nffile_inline.c:83, minilzo.c (redistributed). The attack vector is: nfdump must read and process a…

  • CVE-2019-1010006HigJul 15, 2019
    risk 0.51cvss 7.8epss 0.02

    Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism…

  • CVE-2019-13602HigJul 14, 2019
    risk 0.51cvss 7.8epss 0.02

    An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.

  • CVE-2019-0053HigJul 11, 2019
    risk 0.51cvss 7.8epss 0.01

    Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exploited to bypass veriexec restrictions on Junos OS. A stack-based overflow is present in the handling of environment variables…

  • CVE-2019-5819HigJun 27, 2019
    risk 0.51cvss 7.8epss 0.00

    Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.

  • CVE-2019-12979HigJun 26, 2019
    risk 0.51cvss 7.8epss 0.02

    ImageMagick 7.0.8-34 has a "use of uninitialized value" vulnerability in the SyncImageSettings function in MagickCore/image.c. This is related to AcquireImage in magick/image.c.

  • CVE-2019-12483HigMay 30, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx_code.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2019-5429HigApr 29, 2019
    risk 0.51cvss 7.8epss 0.03

    Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.

  • CVE-2019-11221HigApr 15, 2019
    risk 0.51cvss 7.8epss 0.01

    GPAC 0.7.1 has a buffer overflow issue in gf_import_message() in media_import.c.

  • CVE-2019-9924HigMar 22, 2019
    risk 0.51cvss 7.8epss 0.00

    rbash in Bash before 4.4-beta2 did not prevent the shell user from modifying BASH_CMDS, thus allowing the user to execute any command with the permissions of the shell.

  • CVE-2019-9210HigFeb 27, 2019
    risk 0.51cvss 7.8epss 0.01

    In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)

  • CVE-2019-5780HigFeb 19, 2019
    risk 0.51cvss 7.8epss 0.00

    Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events.

  • CVE-2019-8383HigFeb 17, 2019
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in AdvanceCOMP through 2.1. An invalid memory address occurs in the function adv_png_unfilter_8 in lib/png.c. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly…

  • CVE-2019-7548HigFeb 6, 2019
    risk 0.51cvss 7.8epss 0.02

    SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

  • CVE-2019-1000018HigFeb 4, 2019
    risk 0.51cvss 7.8epss 0.02

    rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable via An authorized SSH user with the…

  • CVE-2019-7310HigFeb 3, 2019
    risk 0.51cvss 7.8epss 0.02

    In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as…

  • CVE-2017-3145HigJan 16, 2019
    risk 0.51cvss 7.5epss 0.28

    BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2,…

  • CVE-2018-16865HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.03

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw…

  • CVE-2018-16864HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.01

    An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate…

  • CVE-2018-4180HigJan 11, 2019
    risk 0.51cvss 7.8epss 0.00

    In macOS High Sierra before 10.13.5, an issue existed in CUPS. This issue was addressed with improved access restrictions.

  • CVE-2019-3500HigJan 2, 2019
    risk 0.51cvss 7.8epss 0.00

    aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.

Page 54 of 210