Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-07-23 | CVE-2019-11730 | A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in... | Debian_linux, Firefox, Firefox_esr, Thunderbird, Leap, Package_hub | 6.5 | ||
2019-09-11 | CVE-2019-16217 | WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled. | Debian_linux, Wordpress | 6.1 | ||
2019-09-11 | CVE-2019-16218 | WordPress before 5.2.3 allows XSS in stored comments. | Debian_linux, Wordpress | 6.1 | ||
2019-09-11 | CVE-2019-16219 | WordPress before 5.2.3 allows XSS in shortcode previews. | Debian_linux, Wordpress | 6.1 | ||
2019-09-11 | CVE-2019-16221 | WordPress before 5.2.3 allows reflected XSS in the dashboard. | Debian_linux, Wordpress | 6.1 | ||
2019-09-11 | CVE-2019-16222 | WordPress before 5.2.3 has an issue with URL sanitization in wp_kses_bad_protocol_once in wp-includes/kses.php that can lead to cross-site scripting (XSS) attacks. | Debian_linux, Wordpress | 6.1 | ||
2020-01-21 | CVE-2019-20387 | repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema. | Debian_linux, Libsolv | 7.5 | ||
2017-09-13 | CVE-2017-2816 | An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write out of bounds resulting in a buffer overflow on the stack. An attacker can construct a malicious OFX file to trigger this vulnerability. | Debian_linux, Libofx | 8.8 | ||
2018-04-24 | CVE-2017-14448 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can cause a heap overflow resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | Debian_linux, Sdl_image | 8.8 | ||
2020-01-08 | CVE-2019-17023 | After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72. | Ubuntu_linux, Debian_linux, Firefox | 6.5 |