| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2008-7291 |
gri before 2.12.18 generates temporary files in an insecure way. Published: November 07, 2019; 7:15:10 PM -0500 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2013-1811 |
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New". Published: November 07, 2019; 6:15:10 PM -0500 |
V3.1: 4.3 MEDIUM V2.0: 4.0 MEDIUM |
| CVE-2013-1809 |
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories. Published: November 07, 2019; 6:15:10 PM -0500 |
V3.1: 7.5 HIGH V2.0: 6.4 MEDIUM |
| CVE-2007-6745 |
clamav 0.91.2 suffers from a floating point exception when using ScanOLE2. Published: November 07, 2019; 6:15:10 PM -0500 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2013-1429 |
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks. Published: November 07, 2019; 5:15:10 PM -0500 |
V3.1: 6.3 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2007-5743 |
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option. Published: November 07, 2019; 5:15:10 PM -0500 |
V3.1: 7.5 HIGH V2.0: 4.3 MEDIUM |
| CVE-2013-1425 |
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions. Published: November 07, 2019; 4:15:10 PM -0500 |
V3.1: 5.5 MEDIUM V2.0: 2.1 LOW |
| CVE-2010-2450 |
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default. Published: November 07, 2019; 4:15:10 PM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2019-3465 |
Rob Richards XmlSecLibs, all versions prior to v3.0.3, as used for example by SimpleSAMLphp, performed incorrect validation of cryptographic signatures in XML messages, allowing an authenticated attacker to impersonate others or elevate privileges by creating a crafted XML message. Published: November 07, 2019; 3:15:11 PM -0500 |
V3.1: 8.8 HIGH V2.0: 6.5 MEDIUM |
| CVE-2012-0051 |
Tahoe-LAFS 1.9.0 fails to ensure integrity which allows remote attackers to corrupt mutable files or directories upon retrieval. Published: November 07, 2019; 1:15:11 PM -0500 |
V3.1: 7.4 HIGH V2.0: 5.8 MEDIUM |
| CVE-2012-0049 |
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server. Published: November 07, 2019; 1:15:11 PM -0500 |
V3.1: 4.3 MEDIUM V2.0: 4.0 MEDIUM |
| CVE-2019-18809 |
A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559. Published: November 07, 2019; 11:15:11 AM -0500 |
V3.1: 4.6 MEDIUM V2.0: 4.9 MEDIUM |
| CVE-2009-5046 |
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22. Published: November 06, 2019; 3:15:09 PM -0500 |
V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2009-5045 |
Dump Servlet information leak in jetty before 6.1.22. Published: November 06, 2019; 3:15:09 PM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2009-5049 |
WebApp JSP Snoop page XSS in jetty though 6.1.21. Published: November 06, 2019; 2:15:11 PM -0500 |
V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2010-2471 |
drupal6 version 6.16 has open redirection Published: November 06, 2019; 1:15:10 PM -0500 |
V3.1: 6.1 MEDIUM V2.0: 5.8 MEDIUM |
| CVE-2011-4900 |
TYPO3 before 4.5.4 allows Information Disclosure in the backend. Published: November 06, 2019; 12:15:11 PM -0500 |
V3.1: 6.5 MEDIUM V2.0: 4.0 MEDIUM |
| CVE-2011-4625 |
simplesamlphp before 1.6.3 (squeeze) and before 1.8.2 (sid) incorrectly handles XML encryption which could allow remote attackers to decrypt or forge messages. Published: November 06, 2019; 10:15:10 AM -0500 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2007-0899 |
There is a possible heap overflow in libclamav/fsg.c before 0.100.0. Published: November 05, 2019; 11:15:10 PM -0500 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2006-4245 |
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition. Published: November 05, 2019; 10:15:10 PM -0500 |
V3.1: 8.1 HIGH V2.0: 6.8 MEDIUM |