CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Dhclient Project2Debian Linux DhclientNov 21, 2024 Nov 27, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 An issue was discovered in dhclient 4.3.1-6 due to an embedded path variable. |
2Debian Xscreensaver Project2Debian Linux XscreensaverNov 21, 2024 Nov 27, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 xscreensaver before 5.14 crashes during activation and leaves the screen unlocked when in Blank Only Mode and when DPMS is disabled, which allows local attackers to access resources without authentication. |
3Debian FedoraprojectPython3Debian Linux FedoraPythonNov 21, 2024 Nov 27, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests. |
3Canonical DebianHaproxy3Debian Linux HaproxyUbuntu LinuxJun 17, 2026 Nov 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The HTTP/2 implementation in HAProxy before 2.0.10 mishandles headers, as demonstrated by carriage return (CR, ASCII 0xd), line feed (LF, ASCII 0xa), and the zero character (NUL, ASCII 0x0), aka Intermediary Encapsulatio...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Nov 27, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists. |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Nov 27, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A heap-based buffer overflow vulnerability was found in the Linux kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrar...Show more |
3Debian PhpZend3Debian Linux PhpZend FrameworkNov 21, 2024 Nov 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6. |
2Debian Lilo Project2Debian Linux LiloNov 21, 2024 Nov 26, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1. |
4Debian OpensuseOracle+1 more4Debian Linux GraalvmLeap+1 moreJun 17, 2026 Nov 26, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can explo...Show more |
2Debian Ruby Lang2Debian Linux RubyJun 17, 2026 Nov 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows HTTP Response Splitting. If a program using WEBrick inserts untrusted input into the response header, an attacker can exploit it to insert a newline...Show more |
2Debian Ruby Lang2Debian Linux RubyJun 17, 2026 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 has a regular expression Denial of Service cause by looping/backtracking. A victim must expose a WEBrick server that uses...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraSquid+1 moreJun 17, 2026 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte v...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraSquid+1 moreJun 17, 2026 Nov 26, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Respon...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraSquid+1 moreJun 17, 2026 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Nov 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that th...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Nov 26, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes a...Show more |
2Debian Yaws2Debian Linux YawsNov 21, 2024 Nov 26, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request. |
2Debian Yubico2Debian Linux Pam ModuleNov 21, 2024 Nov 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use...Show more |
2Debian Phpldapadmin Project2Debian Linux PhpldapadminNov 21, 2024 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via special...Show more |
3Debian Hardlink ProjectRedhat3Debian Linux Enterprise LinuxHardlinkNov 21, 2024 Nov 26, 2019 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks. |