Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-11-20 | CVE-2015-3166 | The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error. | Ubuntu_linux, Debian_linux, Postgresql | N/A | ||
2019-11-20 | CVE-2012-6136 | tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. | Debian_linux, Fedora, Enterprise_linux, Enterprise_linux_desktop, Enterprise_linux_server, Enterprise_linux_workstation, Tuned | N/A | ||
2019-11-19 | CVE-2012-0843 | uzbl: Information disclosure via world-readable cookies storage file | Debian_linux, Uzbl | N/A | ||
2019-11-20 | CVE-2011-1028 | The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. | Debian_linux, Smarty | N/A | ||
2019-11-20 | CVE-2011-0529 | Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP. | Debian_linux, Weborf | N/A | ||
2019-09-30 | CVE-2019-16993 | In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them. | Debian_linux, Phpbb | N/A | ||
2019-11-20 | CVE-2013-1817 | MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. | Debian_linux, Fedora, Mediawiki, Enterprise_linux | N/A | ||
2019-11-20 | CVE-2013-1816 | MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request. | Debian_linux, Fedora, Mediawiki, Enterprise_linux | N/A | ||
2019-11-19 | CVE-2012-0842 | surf: cookie jar has read access from other local user | Debian_linux, Surf | N/A | ||
2019-11-14 | CVE-2011-1490 | A memory leak in rsyslog before 5.7.6 was found in the way deamon processed log messages are logged when multiple rulesets were used and some output batches contained messages belonging to more than one ruleset. A local attacker could cause denial of the rsyslogd daemon service via a log message belonging to more than one ruleset | Debian_linux, Opensuse, Rsyslog | N/A |