Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-11-26 | CVE-2011-3630 | Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable. | Debian_linux, Hardlink, Enterprise_linux | N/A | ||
2019-04-08 | CVE-2019-11010 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file. | Debian_linux, Graphicsmagick, Leap | 6.5 | ||
2019-04-08 | CVE-2019-11006 | In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet. | Debian_linux, Graphicsmagick, Leap | 9.1 | ||
2018-12-17 | CVE-2018-20189 | In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization. | Debian_linux, Graphicsmagick | 6.5 | ||
2018-04-13 | CVE-2017-0359 | diffoscope before 77 writes to arbitrary locations on disk based on the contents of an untrusted archive. | Debian_linux, Diffoscope | N/A | ||
2019-11-15 | CVE-2014-0021 | Chrony before 1.29.1 has traffic amplification in cmdmon protocol | Chrony, Debian_linux, Fedora | N/A | ||
2019-11-25 | CVE-2012-5644 | libuser has information disclosure when moving user's home directory | Debian_linux, Fedora, Libuser, Enterprise_linux | N/A | ||
2019-11-26 | CVE-2011-3596 | Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request. | Debian_linux, Polipo | N/A | ||
2019-11-15 | CVE-2011-2726 | An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL. | Debian_linux, Drupal, Fedora, Enterprise_linux | N/A | ||
2019-11-22 | CVE-2014-6311 | generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated privileges. | Debian_linux, Adaptive_communication_environment | N/A |