Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-08-29 | CVE-2019-14437 | The xiph_SplitHeaders function in modules/demux/xiph.h in VideoLAN VLC media player 3.0.7.1 does not check array bounds properly. As a result, a heap-based buffer over-read can be triggered via a crafted .ogg file. | Debian_linux, Vlc_media_player | 7.8 | ||
2017-07-13 | CVE-2017-11103 | Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service-principal names in a way that violates the Kerberos 5 protocol specification. In _krb5_extract_ticket() the KDC-REP service name must be obtained from the encrypted version stored in 'enc_part' instead of the unencrypted version stored in 'ticket'. Use of the unencrypted version provides an opportunity for successful server impersonation and other attacks. NOTE: this CVE... | Iphone_os, Mac_os_x, Debian_linux, Freebsd, Heimdal, Samba | N/A | ||
2019-11-05 | CVE-2016-1000002 | gdm3 3.14.2 and possibly later has an information leak before screen lock | Debian_linux, Gnome_display_manager, Leap, Enterprise_linux | N/A | ||
2019-11-05 | CVE-2013-6461 | Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits | Debian_linux, Nokogiri, Cloudforms_management_engine, Enterprise_mrg, Openstack, Satellite, Subscription_asset_manager | N/A | ||
2019-11-05 | CVE-2013-6365 | Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions | Debian_linux, Groupware, Opensuse | N/A | ||
2019-11-01 | CVE-2013-4168 | Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. | Debian_linux, Fedora, Smokeping | N/A | ||
2019-10-31 | CVE-2013-2024 | OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0. | Chicken, Debian_linux | N/A | ||
2019-10-31 | CVE-2013-2012 | autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory. | Autojump, Debian_linux | N/A | ||
2019-10-31 | CVE-2013-1951 | A cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.5 and 1.20.x before 1.20.4 and allows remote attackers to inject arbitrary web script or HTML via Lua function names. | Debian_linux, Mediawiki | N/A | ||
2019-10-31 | CVE-2013-1910 | yum does not properly handle bad metadata, which allows an attacker to cause a denial of service and possibly have other unspecified impact via a Trojan horse file in the metadata of a remote repository. | Yum, Debian_linux | N/A |