VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2011-0529HigNov 20, 2019
    risk 0.49cvss 7.5epss 0.01

    Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.

  • CVE-2012-6071HigNov 19, 2019
    risk 0.49cvss 7.5epss 0.01

    nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.

  • CVE-2011-2726HigNov 15, 2019
    risk 0.49cvss 7.5epss 0.02

    An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent…

  • CVE-2016-5285HigNov 15, 2019
    risk 0.49cvss 7.5epss 0.02

    A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

  • CVE-2014-0021HigNov 15, 2019
    risk 0.49cvss 7.5epss 0.04

    Chrony before 1.29.1 has traffic amplification in cmdmon protocol

  • CVE-2012-1155HigNov 14, 2019
    risk 0.49cvss 7.5epss 0.02

    Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to

  • CVE-2010-5108HigNov 13, 2019
    risk 0.49cvss 7.5epss 0.01

    Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.

  • CVE-2010-4657HigNov 13, 2019
    risk 0.49cvss 7.5epss 0.02

    PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

  • CVE-2012-1572HigNov 12, 2019
    risk 0.49cvss 7.5epss 0.01

    OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space

  • CVE-2013-1809HigNov 7, 2019
    risk 0.49cvss 7.5epss 0.02

    Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.

  • CVE-2007-5743HigNov 7, 2019
    risk 0.49cvss 7.5epss 0.01

    viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.

  • CVE-2010-2450HigNov 7, 2019
    risk 0.49cvss 7.5epss 0.01

    The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key…

  • CVE-2019-18804HigNov 7, 2019
    risk 0.49cvss 7.5epss 0.04

    DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.

  • CVE-2009-5045HigNov 6, 2019
    risk 0.49cvss 7.5epss 0.02

    Dump Servlet information leak in jetty before 6.1.22.

  • CVE-2010-2247HigNov 6, 2019
    risk 0.49cvss 7.5epss 0.01

    makepasswd 1.10 default settings generate insecure passwords

  • CVE-2011-4625HigNov 6, 2019
    risk 0.49cvss 7.5epss 0.01

    simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

  • CVE-2013-4412HigNov 4, 2019
    risk 0.49cvss 7.5epss 0.03

    slim has NULL pointer dereference when using crypt() method from glibc 2.17

  • CVE-2013-2600HigNov 1, 2019
    risk 0.49cvss 7.5epss 0.02

    MiniUPnPd has information disclosure use of snprintf()

  • CVE-2019-18421HigOct 31, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV type change operations. To avoid using shadow pagetables for…

  • CVE-2018-5735HigOct 30, 2019
    risk 0.49cvss 7.5epss 0.01

    The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other…

  • CVE-2019-18602HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.02

    OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.

  • CVE-2011-4931HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.01

    gpw generates shorter passwords than required

  • CVE-2009-3723HigOct 29, 2019
    risk 0.49cvss 7.5epss 0.01

    asterisk allows calls on prohibited networks

  • CVE-2012-5577HigOct 28, 2019
    risk 0.49cvss 7.5epss 0.02

    Python keyring lib before 0.10 created keyring files with world-readable permissions.

  • CVE-2019-9232HigSep 27, 2019
    risk 0.49cvss 7.5epss 0.05

    In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID:…

  • CVE-2019-8075HigSep 27, 2019
    risk 0.49cvss 7.5epss 0.03

    Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.

  • CVE-2019-16869HigSep 26, 2019
    risk 0.49cvss 7.5epss 0.08

    Netty before 4.1.42.Final mishandles whitespace before the colon in HTTP headers (such as a "Transfer-Encoding : chunked" line), which leads to HTTP request smuggling.

  • CVE-2019-10092MedSep 26, 2019
    risk 0.49cvss 6.1epss 0.81

    In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server…

  • CVE-2019-5094HigSep 24, 2019
    risk 0.49cvss 7.5epss 0.01

    An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.

  • CVE-2019-16319HigSep 15, 2019
    risk 0.49cvss 7.5epss 0.04

    In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.

  • CVE-2019-16159HigSep 9, 2019
    risk 0.49cvss 7.5epss 0.03

    BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message.…

  • CVE-2016-10937HigSep 8, 2019
    risk 0.49cvss 7.5epss 0.01

    IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.

  • CVE-2019-15892HigSep 3, 2019
    risk 0.49cvss 7.5epss 0.06

    An issue was discovered in Varnish Cache before 6.0.4 LTS, and 6.1.x and 6.2.x before 6.2.1. An HTTP/1 parsing failure allows a remote attacker to trigger an assert by sending crafted HTTP/1 requests. The assert will cause an automatic restart with a clean cache, which makes it…

  • CVE-2019-14513HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.02

    Improper bounds checking in Dnsmasq before 2.76 allows an attacker controlled DNS server to send large DNS packets that result in a read operation beyond the buffer allocated for the packet, a different vulnerability than CVE-2017-14491.

  • CVE-2019-14494HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.

  • CVE-2019-14493HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in OpenCV before 4.1.1. There is a NULL pointer dereference in the function cv::XMLParser::parse at modules/core/src/persistence.cpp.

  • CVE-2019-13565HigJul 26, 2019
    risk 0.49cvss 7.5epss 0.05

    An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity…

  • CVE-2019-13619HigJul 17, 2019
    risk 0.49cvss 7.5epss 0.06

    In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.

  • CVE-2019-10192HigJul 11, 2019
    risk 0.49cvss 7.2epss 0.26

    A heap-buffer overflow vulnerability was found in the Redis hyperloglog data structure versions 3.x before 3.2.13, 4.x before 4.0.14 and 5.x before 5.0.4. By carefully corrupting a hyperloglog using the SETRANGE command, an attacker could trick Redis interpretation of dense HLL…

  • CVE-2019-12474HigJul 10, 2019
    risk 0.49cvss 7.5epss 0.02

    Wikimedia MediaWiki 1.23.0 through 1.32.1 has an information leak. Privileged API responses that include whether a recent change has been patrolled may be cached publicly. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2019-12473HigJul 10, 2019
    risk 0.49cvss 7.5epss 0.02

    Wikimedia MediaWiki 1.27.0 through 1.32.1 might allow DoS. Passing invalid titles to the API could cause a DoS by querying the entire watchlist table. Fixed in 1.32.2, 1.31.2, 1.30.2 and 1.27.6.

  • CVE-2019-8323HigJun 17, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.

  • CVE-2019-8322HigJun 17, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

  • CVE-2019-8321HigJun 17, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.

  • CVE-2019-8325HigJun 17, 2019
    risk 0.49cvss 7.5epss 0.03

    An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

  • CVE-2019-12482HigMay 30, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in GPAC 0.7.1. There is a NULL pointer dereference in the function gf_isom_get_original_format_type at isomedia/drm_sample.c in libgpac.a, as demonstrated by MP4Box.

  • CVE-2019-12295HigMay 23, 2019
    risk 0.49cvss 7.5epss 0.04

    In Wireshark 3.0.0 to 3.0.1, 2.6.0 to 2.6.8, and 2.4.0 to 2.4.14, the dissection engine could crash. This was addressed in epan/packet.c by restricting the number of layers and consequently limiting recursion.

  • CVE-2019-2602HigApr 23, 2019
    risk 0.49cvss 7.5epss 0.04

    Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with…

  • CVE-2019-3883HigApr 17, 2019
    risk 0.49cvss 7.5epss 0.08

    In 389-ds-base up to version 1.4.1.2, requests are handled by workers threads. Each sockets will be waited by the worker for at most 'ioblocktimeout' seconds. However this timeout applies only for un-encrypted requests. Connections using SSL/TLS are not taking this timeout into…

  • CVE-2019-3842HigApr 9, 2019
    risk 0.49cvss 7.0epss 0.01

    In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be…

Page 68 of 210