CVEs (10,002)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Baseurl Debian2Debian Linux YumNov 21, 2024 Oct 31, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository. |
2Debian Mumble2Debian Linux MumbleNov 21, 2024 Oct 31, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Mumble: murmur-server has DoS due to malformed client query |
2Burn Project Debian2Burn Debian LinuxNov 21, 2024 Oct 31, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 burn allows file names to escape via mishandled quotation marks |
2Debian Python Docutils Project2Debian Linux Python DocutilsNov 21, 2024 Oct 31, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 python-docutils allows insecure usage of temporary files |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Oct 31, 2019 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Oct 31, 2019 N/A· v4 6.8 MEDIUM· v3 6.9 MEDIUM· v2 An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 31, 2019 N/A· v4 8.8 HIGH· v3 8.5 HIGH· v2 An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->max_mapped_gfn is used by the functions p2m_resolve_translation_fault() a...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 31, 2019 N/A· v4 8.8 HIGH· v3 8.5 HIGH· v2 An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exc...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Oct 31, 2019 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations. There are issues with restartable PV t...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 31, 2019 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall. hypercall_create_continuation() is a variadic function which uses a printf-like...Show more |
2Debian Transmissionbt2Debian Linux TransmissionNov 21, 2024 Oct 30, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame. |
2Debian Transmissionbt2Debian Linux TransmissionNov 21, 2024 Oct 30, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link. |
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC r...Show more |
2Debian Ikiwiki2Debian Linux IkiwikiNov 21, 2024 Oct 29, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks. |
2Debian Openafs2Debian Linux OpenafsJun 17, 2026 Oct 29, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer. |
2Debian Openafs2Debian Linux OpenafsJun 17, 2026 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer. |
4Canonical DebianLibvnc Project+1 more9Debian Linux LibvncserverSimatic Itc1500 Firmware+6 moreJun 17, 2026 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with...Show more |
2Debian Gpw Project2Debian Linux GpwNov 21, 2024 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 gpw generates shorter passwords than required |
2Debian Grsecurity2Debian Linux PaxtestNov 21, 2024 Oct 29, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 paxtest handles temporary files insecurely |
2Debian Sangoma2Asterisk Debian LinuxNov 21, 2024 Oct 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 asterisk allows calls on prohibited networks |