CVEs (10,002)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OpensuseRsyslog3Debian Linux OpensuseRsyslogNov 21, 2024 Nov 14, 2019 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when $RepeatedMsgReduction was enabled. A local attacker could use this flaw to cause a denial of the rsyslogd daemon se...Show more |
4Debian OpensuseRedhat+1 more4Debian Linux Enterprise LinuxOpensuse+1 moreNov 21, 2024 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string. |
2Debian Tesseract Project2Debian Linux TesseractNov 21, 2024 Nov 14, 2019 N/A· v4 4.7 MEDIUM· v3 6.3 MEDIUM· v2 In tesseract 2.03 and 2.04, an attacker can rewrite an arbitrary user file by guessing the PID and creating a link to the user's file. |
2Debian V86d Project2Debian Linux V86dNov 21, 2024 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other consequences. |
2Debian Phpbb2Debian Linux PhpbbNov 21, 2024 Nov 14, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag. |
2Debian Edgewall2Debian Linux TracNov 21, 2024 Nov 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions. |
2Debian Pithos Project2Debian Linux PithosNov 21, 2024 Nov 13, 2019 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 pithos before 0.3.5 allows overwrite of arbitrary files via symlinks. |
3Consolekit Project DebianRedhat3Consolekit Debian LinuxEnterprise LinuxNov 21, 2024 Nov 13, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session. |
5Debian FedoraprojectOpensuse+2 more5Debian Linux Enterprise LinuxFedora+2 moreNov 21, 2024 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules. |
3Debian PhpRedhat3Debian Linux Enterprise LinuxPhpNov 21, 2024 Nov 13, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output. |
2Debian Freedesktop2Debian Linux PopplerNov 21, 2024 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack. |
2Debian Freedesktop2Debian Linux PopplerNov 21, 2024 Nov 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts. |
2Debian Offlineimap2Debian Linux OfflineimapNov 21, 2024 Nov 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies. |
2Debian Offlineimap2Debian Linux OfflineimapNov 21, 2024 Nov 13, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks. |
2Debian Trilexnet2Debian Linux LetodmsNov 21, 2024 Nov 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 letodms 3.3.6 has CSRF via change password |
2Debian Trilexnet2Debian Linux LetodmsNov 21, 2024 Nov 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar |
2Debian Gnu2Debian Linux FribidiJun 17, 2026 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering...Show more |
2Debian Ettercap Project2Debian Linux EttercapNov 21, 2024 Nov 12, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack. |
2Babiloo Project Debian2Babiloo Debian LinuxNov 21, 2024 Nov 12, 2019 N/A· v4 5.5 MEDIUM· v3 3.3 LOW· v2 babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files. |
2Debian Rubyonrails2Debian Linux RailsNov 21, 2024 Nov 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks. |