VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2020-6061CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.05

    An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this…

  • CVE-2020-8086CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.02

    The mod_auth_ldap and mod_auth_ldap2 Community Modules through 2020-01-27 for Prosody incompletely verify the XMPP address passed to the is_admin() function. This grants remote entities admin-only functionality if their username matches the username of a local admin.

  • CVE-2014-0048CriJan 2, 2020
    risk 0.64cvss 9.8epss 0.07

    An issue was found in Docker before 1.6.0. Some programs and scripts in Docker are downloaded via HTTP and then executed or used in unsafe ways.

  • CVE-2019-19951CriDec 24, 2019
    risk 0.64cvss 9.8epss 0.03

    In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.

  • CVE-2019-19950CriDec 24, 2019
    risk 0.64cvss 9.8epss 0.03

    In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.

  • CVE-2019-19948CriDec 24, 2019
    risk 0.64cvss 9.8epss 0.04

    In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer overflow in the function WriteSGIImage of coders/sgi.c.

  • CVE-2012-6094CriDec 20, 2019
    risk 0.64cvss 9.8epss 0.02

    cups (Common Unix Printing System) 'Listen localhost:631' option not honored correctly which could provide unauthorized access to the system

  • CVE-2014-0175CriDec 13, 2019
    risk 0.64cvss 9.8epss 0.02

    mcollective has a default password set at install

  • CVE-2019-19725CriDec 11, 2019
    risk 0.64cvss 9.8epss 0.03

    sysstat through 12.2.0 has a double free in check_file_actlst in sa_common.c.

  • CVE-2012-1577CriDec 10, 2019
    risk 0.64cvss 9.8epss 0.02

    lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0.

  • CVE-2013-2745CriDec 4, 2019
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0

  • CVE-2019-14897CriNov 29, 2019
    risk 0.64cvss 9.8epss 0.03

    A stack-based buffer overflow was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations…

  • CVE-2019-14895CriNov 29, 2019
    risk 0.64cvss 9.8epss 0.08

    A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This…

  • CVE-2019-19330CriNov 27, 2019
    risk 0.64cvss 9.8epss 0.04

    The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulation Attacks.

  • CVE-2019-14896CriNov 27, 2019
    risk 0.64cvss 9.8epss 0.09

    A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called…

  • CVE-2014-6311CriNov 22, 2019
    risk 0.64cvss 9.8epss 0.02

    generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges.

  • CVE-2014-6310CriNov 22, 2019
    risk 0.64cvss 9.8epss 0.05

    Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.

  • CVE-2011-0703CriNov 15, 2019
    risk 0.64cvss 9.8epss 0.01

    In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may allow an attacker to overtake an administrator X11 session.

  • CVE-2010-3438CriNov 12, 2019
    risk 0.64cvss 9.8epss 0.02

    libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.

  • CVE-2011-2897CriNov 12, 2019
    risk 0.64cvss 9.8epss 0.02

    gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

  • CVE-2008-7291CriNov 8, 2019
    risk 0.64cvss 9.8epss 0.01

    gri before 2.12.18 generates temporary files in an insecure way.

  • CVE-2007-6745CriNov 7, 2019
    risk 0.64cvss 9.8epss 0.02

    clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

  • CVE-2007-0899CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

  • CVE-2006-3100CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    termpkg 3.3 suffers from buffer overflow.

  • CVE-2006-0061CriNov 6, 2019
    risk 0.64cvss 9.8epss 0.02

    xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.

  • CVE-2013-1910CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.03

    yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository.

  • CVE-2009-5043CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.01

    burn allows file names to escape via mishandled quotation marks

  • CVE-2009-5041CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.01

    overkill has buffer overflow via long player names that can corrupt data on the server machine

  • CVE-2019-18425CriOct 31, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table…

  • CVE-2010-0748CriOct 30, 2019
    risk 0.64cvss 9.8epss 0.02

    Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.

  • CVE-2019-17455CriOct 10, 2019
    risk 0.64cvss 9.8epss 0.03

    Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.

  • CVE-2019-17133CriOct 4, 2019
    risk 0.64cvss 9.8epss 0.07

    In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.

  • CVE-2019-15941CriSep 25, 2019
    risk 0.64cvss 9.8epss 0.02

    OpenID Connect Issuer in LemonLDAP::NG 2.x through 2.0.5 may allow an attacker to bypass access control rules via a crafted OpenID Connect authorization request. To be vulnerable, there must exist an OIDC Relaying party within the LemonLDAP configuration with weaker access…

  • CVE-2019-5481CriSep 16, 2019
    risk 0.64cvss 9.8epss 0.07

    Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

  • CVE-2019-13486CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.

  • CVE-2019-13485CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter to history.c.

  • CVE-2019-13484CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a buffer overflow exists in the status-log viewer CGI because of expansion in appfeed.c.

  • CVE-2019-13455CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c.

  • CVE-2019-13452CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a buffer overflow vulnerability exists in reportlog.c.

  • CVE-2019-13451CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a buffer overflow vulnerability exists in history.c.

  • CVE-2019-13273CriAug 27, 2019
    risk 0.64cvss 9.8epss 0.02

    In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.

  • CVE-2019-15505CriAug 23, 2019
    risk 0.64cvss 9.8epss 0.08

    drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through 5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote via usbip or usbredir).

  • CVE-2019-9850CriAug 15, 2019
    risk 0.64cvss 9.8epss 0.03

    LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can…

  • CVE-2019-11187CriAug 15, 2019
    risk 0.64cvss 9.8epss 0.02

    Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.

  • CVE-2019-14809CriAug 13, 2019
    risk 0.64cvss 9.8epss 0.08

    net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications. This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port…

  • CVE-2019-13917CriJul 25, 2019
    risk 0.64cvss 9.8epss 0.09

    Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion for items that can be controlled by an attacker (e.g., $local_part or $domain).

  • CVE-2019-1010174CriJul 25, 2019
    risk 0.64cvss 9.8epss 0.05

    CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no string sanitization is done…

  • CVE-2019-11709CriJul 23, 2019
    risk 0.64cvss 9.8epss 0.02

    Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This…

  • CVE-2019-1010238CriJul 19, 2019
    risk 0.64cvss 9.8epss 0.06

    Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is:…

  • CVE-2019-13962CriJul 18, 2019
    risk 0.64cvss 9.8epss 0.04

    lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.

Page 7 of 210