Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-11-14 | CVE-2012-1155 | Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to | Debian_linux, Fedora, Moodle, Enterprise_linux | N/A | ||
2018-03-27 | CVE-2018-8048 | In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment. | Debian_linux, Loofah | 6.1 | ||
2019-11-20 | CVE-2015-3167 | contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack. | Ubuntu_linux, Debian_linux, Postgresql | N/A | ||
2019-11-20 | CVE-2015-3166 | The snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does not properly handle system-call errors, which allows attackers to obtain sensitive information or have other unspecified impact via unknown vectors, as demonstrated by an out-of-memory error. | Ubuntu_linux, Debian_linux, Postgresql | N/A | ||
2019-11-20 | CVE-2012-6136 | tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. | Debian_linux, Fedora, Enterprise_linux, Enterprise_linux_desktop, Enterprise_linux_server, Enterprise_linux_workstation, Tuned | N/A | ||
2019-11-19 | CVE-2012-0843 | uzbl: Information disclosure via world-readable cookies storage file | Debian_linux, Uzbl | N/A | ||
2019-11-20 | CVE-2011-1028 | The $smarty.template variable in Smarty3 allows attackers to possibly execute arbitrary PHP code via the sysplugins/smarty_internal_compile_private_special_variable.php file. | Debian_linux, Smarty | N/A | ||
2019-11-20 | CVE-2011-0529 | Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP. | Debian_linux, Weborf | N/A | ||
2019-09-30 | CVE-2019-16993 | In phpBB before 3.1.7-PL1, includes/acp/acp_bbcodes.php has improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An actual CSRF attack is possible if an attacker also manages to retrieve the session id of a reauthenticated administrator prior to targeting them. | Debian_linux, Phpbb | N/A | ||
2019-11-20 | CVE-2013-1817 | MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. | Debian_linux, Fedora, Mediawiki, Enterprise_linux | N/A |