VYPR

Vendor CVEs

Debian

All CVEs

10,468 total · sorted by risk
  • CVE-2019-13746MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2019-13745MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-13744MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in cookies in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2019-13743MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page.

  • CVE-2019-13742MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name.

  • CVE-2019-13740MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2019-13739MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2019-13738MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page.

  • CVE-2019-13737MedDec 10, 2019
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in autocomplete in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2013-2625MedNov 27, 2019
    risk 0.42cvss 6.5epss 0.01

    An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified

  • CVE-2019-18676HigNov 26, 2019
    risk 0.42cvss 7.5epss 0.09

    An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurring before normal security…

  • CVE-2011-3617MedNov 26, 2019
    risk 0.42cvss 6.5epss 0.01

    Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases.

  • CVE-2019-19246HigNov 25, 2019
    risk 0.42cvss 7.5epss 0.03

    Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.

  • CVE-2012-5521MedNov 25, 2019
    risk 0.42cvss 6.5epss 0.01

    quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal

  • CVE-2015-5694MedNov 22, 2019
    risk 0.42cvss 6.5epss 0.02

    Designate does not enforce the DNS protocol limit concerning record set sizes

  • CVE-2019-19204HigNov 21, 2019
    risk 0.42cvss 7.5epss 0.07

    An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.

  • CVE-2012-3543HigNov 21, 2019
    risk 0.42cvss 7.5epss 0.03

    mono 2.10.x ASP.NET Web Form Hash collision DoS

  • CVE-2012-2350HigNov 21, 2019
    risk 0.42cvss 7.5epss 0.01

    pam_shield before 0.9.4: Default configuration does not perform protective action

  • CVE-2015-3167HigNov 20, 2019
    risk 0.42cvss 7.5epss 0.04

    contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.

  • CVE-2019-19074HigNov 18, 2019
    risk 0.42cvss 7.5epss 0.04

    A memory leak in the ath9k_wmi_cmd() function in drivers/net/wireless/ath/ath9k/wmi.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-728c1e2a05e4.

  • CVE-2013-7089HigNov 15, 2019
    risk 0.42cvss 7.5epss 0.02

    ClamAV before 0.97.7: dbg_printhex possible information leak

  • CVE-2018-12207MedNov 14, 2019
    risk 0.42cvss 6.5epss 0.01

    Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.

  • CVE-2010-4653MedNov 13, 2019
    risk 0.42cvss 6.5epss 0.02

    An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

  • CVE-2010-3299MedNov 12, 2019
    risk 0.42cvss 6.5epss 0.01

    The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.

  • CVE-2010-3439MedNov 12, 2019
    risk 0.42cvss 6.5epss 0.02

    It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.

  • CVE-2019-18848HigNov 12, 2019
    risk 0.42cvss 7.5epss 0.01

    The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.

  • CVE-2019-14824MedNov 8, 2019
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.

  • CVE-2011-4900MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    TYPO3 before 4.5.4 allows Information Disclosure in the backend.

  • CVE-2013-5123MedNov 5, 2019
    risk 0.42cvss 5.9epss 0.08

    The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

  • CVE-2013-6461MedNov 5, 2019
    risk 0.42cvss 6.5epss 0.02

    Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits

  • CVE-2013-6460MedNov 5, 2019
    risk 0.42cvss 6.5epss 0.02

    Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents

  • CVE-2012-6123MedOct 31, 2019
    risk 0.42cvss 6.5epss 0.01

    Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack."

  • CVE-2019-18420MedOct 31, 2019
    risk 0.42cvss 6.5epss 0.03

    An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like format string to interpret its parameters. Error handling…

  • CVE-2019-17596HigOct 24, 2019
    risk 0.42cvss 7.5epss 0.05

    Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic containing an invalid DSA public key. There are several attack scenarios, such as traffic from a client to a server that verifies client certificates.

  • CVE-2019-18408HigOct 24, 2019
    risk 0.42cvss 7.5epss 0.04

    archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.

  • CVE-2019-18197HigOct 18, 2019
    risk 0.42cvss 7.5epss 0.04

    In xsltCopyText in transform.c in libxslt 1.1.33, a pointer variable isn't reset under certain circumstances. If the relevant memory area happened to be freed and reused in a certain way, a bounds check could fail and memory outside a buffer could be written to, or uninitialized…

  • CVE-2019-17673HigOct 17, 2019
    risk 0.42cvss 7.5epss 0.03

    WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.

  • CVE-2019-17402MedOct 9, 2019
    risk 0.42cvss 6.5epss 0.02

    Exiv2 0.27.2 allows attackers to trigger a crash in Exiv2::getULong in types.cpp when called from Exiv2::Internal::CiffDirectory::readDirectory in crwimage_int.cpp, because there is no validation of the relationship of the total size to the offset and size.

  • CVE-2019-17348MedOct 8, 2019
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service because of an incompatibility between Process Context Identifiers (PCID) and shadow-pagetable switching.

  • CVE-2019-17345MedOct 8, 2019
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Xen 4.8.x through 4.11.x allowing x86 PV guest OS users to cause a denial of service because mishandling of failed IOMMU operations causes a bug check during the cleanup of a crashed guest.

  • CVE-2019-17344MedOct 8, 2019
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service by leveraging a long-running operation that exists to support restartability of PTE updates.

  • CVE-2018-14882HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.

  • CVE-2018-14881HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.05

    The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).

  • CVE-2018-14880HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.05

    The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().

  • CVE-2018-14470HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The Babel parser in tcpdump before 4.9.3 has a buffer over-read in print-babel.c:babel_print_v2().

  • CVE-2018-14469HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.05

    The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

  • CVE-2018-14468HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print().

  • CVE-2018-14467HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_MP).

  • CVE-2018-14466HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The Rx parser in tcpdump before 4.9.3 has a buffer over-read in print-rx.c:rx_cache_find() and rx_cache_insert().

  • CVE-2018-14465HigOct 3, 2019
    risk 0.42cvss 7.5epss 0.04

    The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

Page 98 of 210