| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2012-3409 |
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation Published: December 20, 2019; 9:15:11 AM -0500 |
V3.1: 7.8 HIGH V2.0: 4.6 MEDIUM |
| CVE-2019-19906 |
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl. Published: December 19, 2019; 1:15:12 PM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2012-2237 |
Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.4.x before 1.4.3 and 1.5.x before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript innerHTML as used when generating login forms, (2) links or (3) resources URLs, and (4) the Display name in a user profile. Published: December 17, 2019; 1:15:12 PM -0500 |
V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2019-19830 |
_core_/plugins/medias in SPIP 3.2.x before 3.2.7 allows remote authenticated authors to inject content into the database. Published: December 17, 2019; 12:15:14 AM -0500 |
V3.1: 6.5 MEDIUM V2.0: 4.0 MEDIUM |
| CVE-2019-19331 |
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for each such uncached message. For example, a few thousand A records can be squashed into one DNS message (limit is 64kB). Published: December 16, 2019; 11:15:11 AM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2019-19783 |
An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail account on the service can use a sieve script containing a fileinto directive to create any mailbox with administrator privileges, because of folder mishandling in autosieve_createfolder() in imap/lmtp_sieve.c. Published: December 16, 2019; 9:15:12 AM -0500 |
V3.1: 6.5 MEDIUM V2.0: 3.5 LOW |
| CVE-2014-8650 |
python-requests-Kerberos through 0.5 does not handle mutual authentication Published: December 15, 2019; 5:15:12 PM -0500 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2014-8561 |
imagemagick 6.8.9.6 has remote DOS via infinite loop Published: December 15, 2019; 5:15:11 PM -0500 |
V3.1: 6.5 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2014-4913 |
ZF2014-03 has a potential cross site scripting vector in multiple view helpers Published: December 15, 2019; 5:15:11 PM -0500 |
V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2014-3495 |
duplicity 0.6.24 has improper verification of SSL certificates Published: December 13, 2019; 9:15:12 AM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2014-2387 |
Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities Published: December 13, 2019; 9:15:11 AM -0500 |
V3.1: 4.4 MEDIUM V2.0: 4.6 MEDIUM |
| CVE-2014-0175 |
mcollective has a default password set at install Published: December 13, 2019; 8:15:10 AM -0500 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2019-12420 |
In Apache SpamAssassin before 3.4.3, a message can be crafted in a way to use excessive resources. Upgrading to SA 3.4.3 as soon as possible is the recommended fix but details will not be shared publicly. Published: December 12, 2019; 6:15:12 PM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2018-11805 |
In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should only use update channels or 3rd party .cf files from trusted places. Published: December 12, 2019; 6:15:11 PM -0500 |
V3.1: 6.7 MEDIUM V2.0: 7.2 HIGH |
| CVE-2019-17358 |
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module. Published: December 12, 2019; 9:15:16 AM -0500 |
V3.1: 8.1 HIGH V2.0: 5.5 MEDIUM |
| CVE-2013-7371 |
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370) Published: December 11, 2019; 10:15:13 AM -0500 |
V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2013-7370 |
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware Published: December 11, 2019; 9:15:09 AM -0500 |
V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2013-4245 |
Orca has arbitrary code execution due to insecure Python module load Published: December 11, 2019; 9:15:09 AM -0500 |
V3.1: 7.3 HIGH V2.0: 4.4 MEDIUM |
| CVE-2013-4158 |
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) Published: December 11, 2019; 8:15:10 AM -0500 |
V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2019-19604 |
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository. Published: December 10, 2019; 7:15:13 PM -0500 |
V3.1: 7.8 HIGH V2.0: 9.3 HIGH |