Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-11-15 | CVE-2011-2910 | The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges which can allow possible privilege escalation. | Debian_linux, Ax25\-Tools | N/A | ||
2019-11-22 | CVE-2015-7810 | libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files | Debian_linux, Fedora, Enterprise_linux, Libbluray | N/A | ||
2019-11-22 | CVE-2015-5694 | Designate does not enforce the DNS protocol limit concerning record set sizes | Debian_linux, Designate, Enterprise_linux_openstack_platform | N/A | ||
2019-11-22 | CVE-2014-6310 | Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function. | Chicken, Debian_linux | N/A | ||
2019-11-21 | CVE-2014-1936 | rc before 1.7.1-5 insecurely creates temporary files. | Debian_linux, Rc | N/A | ||
2019-11-13 | CVE-2010-4817 | pithos before 0.3.5 allows overwrite of arbitrary files via symlinks. | Debian_linux, Pithos | N/A | ||
2019-11-21 | CVE-2012-3543 | mono 2.10.x ASP.NET Web Form Hash collision DoS | Ubuntu_linux, Debian_linux, Mono | N/A | ||
2019-11-14 | CVE-2012-1155 | Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to | Debian_linux, Fedora, Moodle, Enterprise_linux | N/A | ||
2018-03-27 | CVE-2018-8048 | In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment. | Debian_linux, Loofah | 6.1 | ||
2019-11-20 | CVE-2015-3167 | contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack. | Ubuntu_linux, Debian_linux, Postgresql | N/A |