CVEs (10,002)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Cor Entertainment DebianFedoraproject3Alien Arena Debian LinuxFedoraNov 21, 2024 Nov 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command. |
3Debian FedoraprojectLibpoe Component Irc Perl Project3Debian Linux FedoraLibpoe Component Irc PerlNov 21, 2024 Nov 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which...Show more |
2Debian Gargoyle Project2Debian Linux GargoyleNov 21, 2024 Nov 12, 2019 N/A· v4 4.8 MEDIUM· v3 4.4 MEDIUM· v2 If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. This can allow a local user to trick another user into running gargoyle in a directory with a cracked...Show more |
2Debian Openstack2Debian Linux KeystoneNov 21, 2024 Nov 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space |
2Debian Json Jwt Project2Debian Linux Json JwtJun 17, 2026 Nov 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string. |
2Atop Project Debian2Atop Debian LinuxNov 21, 2024 Nov 12, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 atop: symlink attack possible due to insecure tempfile handling |
3Debian GnomeRedhat3Debian Linux Enterprise LinuxGdk PixbufNov 21, 2024 Nov 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraTnef+1 moreJun 17, 2026 Nov 11, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read...Show more |
liboping 1.3.2 allows users reading arbitrary files upon the local system. |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxJun 17, 2026 Nov 8, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes,...Show more |
2Debian Gri Project2Debian Linux GriNov 21, 2024 Nov 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gri before 2.12.18 generates temporary files in an insecure way. |
2Debian Mantisbt2Debian Linux MantisbtNov 21, 2024 Nov 7, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New". |
2Debian Gambas Project2Debian Linux GambasNov 21, 2024 Nov 7, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories. |
2Clamav Debian2Clamav Debian LinuxNov 21, 2024 Nov 7, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 clamav 0.91.2 suffers from a floating point exception when using ScanOLE2. |
2Canonical Debian3Debian Linux LintianUbuntu LinuxNov 21, 2024 Nov 7, 2019 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks. |
2Debian Viewvc2Debian Linux ViewvcNov 21, 2024 Nov 7, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option. |
2Debian Ldap Git Backup Project2Debian Linux Ldap Git BackupNov 21, 2024 Nov 7, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions. |
2Debian Shibboleth2Debian Linux Service ProviderNov 21, 2024 Nov 7, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmod...Show more |
3Debian SimplesamlphpXmlseclibs Project3Debian Linux SimplesamlphpXmlseclibsJun 17, 2026 Nov 7, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate o...Show more |
2Debian Tahoe Lafs2Debian Linux Tahoe LafsNov 21, 2024 Nov 7, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval. |