| Vuln ID | Summary | CVSS Severity |
|---|---|---|
| CVE-2013-2600 |
MiniUPnPd has information disclosure use of snprintf() Published: November 01, 2019; 8:15:10 AM -0400 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2012-6123 |
Chicken before 4.8.0 does not properly handle NUL bytes in certain strings, which allows an attacker to conduct "poisoned NUL byte attack." Published: October 31, 2019; 5:15:11 PM -0400 |
V3.1: 6.5 MEDIUM V2.0: 5.0 MEDIUM |
| CVE-2013-2024 |
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0. Published: October 31, 2019; 4:15:10 PM -0400 |
V3.1: 8.8 HIGH V2.0: 9.0 HIGH |
| CVE-2013-2012 |
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory. Published: October 31, 2019; 4:15:10 PM -0400 |
V3.1: 7.3 HIGH V2.0: 4.4 MEDIUM |
| CVE-2013-1951 |
A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names. Published: October 31, 2019; 4:15:10 PM -0400 |
V3.1: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2013-1934 |
A cross-site scripting (XSS) vulnerability in the configuration report page (adm_config_report.php) in MantisBT 1.2.0rc1 before 1.2.14 allows remote authenticated users to inject arbitrary web script or HTML via a complex value. Published: October 31, 2019; 4:15:10 PM -0400 |
V3.1: 5.4 MEDIUM V2.0: 3.5 LOW |
| CVE-2013-1910 |
yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository. Published: October 31, 2019; 3:15:10 PM -0400 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2010-2490 |
Mumble: murmur-server has DoS due to malformed client query Published: October 31, 2019; 12:15:10 PM -0400 |
V3.1: 6.5 MEDIUM V2.0: 4.0 MEDIUM |
| CVE-2009-5043 |
burn allows file names to escape via mishandled quotation marks Published: October 31, 2019; 12:15:10 PM -0400 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2009-5042 |
python-docutils allows insecure usage of temporary files Published: October 31, 2019; 12:15:10 PM -0400 |
V3.1: 9.1 CRITICAL V2.0: 6.4 MEDIUM |
| CVE-2010-0749 |
Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame. Published: October 30, 2019; 7:15:10 PM -0400 |
V3.1: 5.3 MEDIUM V2.0: 5.0 MEDIUM |
| CVE-2010-0748 |
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link. Published: October 30, 2019; 7:15:10 PM -0400 |
V3.1: 9.8 CRITICAL V2.0: 7.5 HIGH |
| CVE-2010-0747 |
drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725. Published: October 30, 2019; 7:15:09 PM -0400 |
V3.1: 7.8 HIGH V2.0: 4.6 MEDIUM |
| CVE-2010-0207 |
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers. Published: October 30, 2019; 5:15:11 PM -0400 |
V3.1: 5.5 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2010-0206 |
xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects. Published: October 30, 2019; 5:15:11 PM -0400 |
V3.1: 5.5 MEDIUM V2.0: 4.3 MEDIUM |
| CVE-2018-5735 |
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected. Published: October 30, 2019; 10:15:11 AM -0400 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2011-1408 |
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks. Published: October 29, 2019; 4:15:10 PM -0400 |
V3.1: 8.2 HIGH V2.0: 6.4 MEDIUM |
| CVE-2019-15681 |
LibVNC commit before d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a contains a memory leak (CWE-655) in VNC server code, which allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This attack appear to be exploitable via network connectivity. These vulnerabilities have been fixed in commit d01e1bb4246323ba6fcee3b82ef1faa9b1dac82a. Published: October 29, 2019; 3:15:18 PM -0400 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2011-4931 |
gpw generates shorter passwords than required Published: October 29, 2019; 3:15:13 PM -0400 |
V3.1: 7.5 HIGH V2.0: 5.0 MEDIUM |
| CVE-2010-3373 |
paxtest handles temporary files insecurely Published: October 29, 2019; 3:15:12 PM -0400 |
V3.1: 5.5 MEDIUM V2.0: 2.1 LOW |