Search Results (Refine Search)

Search Parameters:
  • Keyword (text search): cpe:/o:debian:debian_linux:9.0
There are 1,965 matching records.
Displaying matches 261 through 280.
Vuln ID Summary CVSS Severity
CVE-2011-2897

gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw

Published: November 12, 2019; 9:15:10 AM -0500
V3.1: 9.8 CRITICAL
V2.0: 7.5 HIGH
CVE-2009-3614

liboping 1.3.2 allows users reading arbitrary files upon the local system.

Published: November 08, 2019; 10:15:10 PM -0500
V3.1: 3.3 LOW
V2.0: 2.1 LOW
CVE-2008-7291

gri before 2.12.18 generates temporary files in an insecure way.

Published: November 07, 2019; 7:15:10 PM -0500
V3.1: 9.8 CRITICAL
V2.0: 7.5 HIGH
CVE-2013-1809

Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.

Published: November 07, 2019; 6:15:10 PM -0500
V3.1: 7.5 HIGH
V2.0: 6.4 MEDIUM
CVE-2007-6745

clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.

Published: November 07, 2019; 6:15:10 PM -0500
V3.1: 9.8 CRITICAL
V2.0: 7.5 HIGH
CVE-2013-1429

Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.

Published: November 07, 2019; 5:15:10 PM -0500
V3.1: 6.3 MEDIUM
V2.0: 4.3 MEDIUM
CVE-2007-5743

viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.

Published: November 07, 2019; 5:15:10 PM -0500
V3.1: 7.5 HIGH
V2.0: 4.3 MEDIUM
CVE-2013-1425

ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.

Published: November 07, 2019; 4:15:10 PM -0500
V3.1: 5.5 MEDIUM
V2.0: 2.1 LOW
CVE-2010-2450

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

Published: November 07, 2019; 4:15:10 PM -0500
V3.1: 7.5 HIGH
V2.0: 5.0 MEDIUM
CVE-2019-3465

Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message.

Published: November 07, 2019; 3:15:11 PM -0500
V3.1: 8.8 HIGH
V2.0: 6.5 MEDIUM
CVE-2012-0051

Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval.

Published: November 07, 2019; 1:15:11 PM -0500
V3.1: 7.4 HIGH
V2.0: 5.8 MEDIUM
CVE-2012-0049

OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.

Published: November 07, 2019; 1:15:11 PM -0500
V3.1: 4.3 MEDIUM
V2.0: 4.0 MEDIUM
CVE-2011-4625

simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages.

Published: November 06, 2019; 10:15:10 AM -0500
V3.1: 7.5 HIGH
V2.0: 5.0 MEDIUM
CVE-2007-0899

There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

Published: November 05, 2019; 11:15:10 PM -0500
V3.1: 9.8 CRITICAL
V2.0: 7.5 HIGH
CVE-2006-4245

archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.

Published: November 05, 2019; 10:15:10 PM -0500
V3.1: 8.1 HIGH
V2.0: 6.8 MEDIUM
CVE-2013-5123

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

Published: November 05, 2019; 5:15:10 PM -0500
V3.1: 5.9 MEDIUM
V2.0: 4.3 MEDIUM
CVE-2013-6275

Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

Published: November 05, 2019; 2:15:10 PM -0500
V3.1: 6.5 MEDIUM
V2.0: 4.3 MEDIUM
CVE-2013-6461

Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits

Published: November 05, 2019; 10:15:11 AM -0500
V3.1: 6.5 MEDIUM
V2.0: 4.3 MEDIUM
CVE-2013-6460

Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents

Published: November 05, 2019; 10:15:11 AM -0500
V3.1: 6.5 MEDIUM
V2.0: 4.3 MEDIUM
CVE-2016-1000002

gdm3 3.14.2 and possibly later has an information leak before screen lock

Published: November 05, 2019; 9:15:13 AM -0500
V3.1: 2.4 LOW
V2.0: 2.1 LOW