Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-12-10 | CVE-2016-1000108 | yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. | Debian_linux, Yaws | N/A | ||
2019-11-29 | CVE-2015-1855 | verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters. | Debian_linux, Puppet_agent, Puppet_enterprise, Ruby, Trunk | N/A | ||
2019-12-11 | CVE-2013-7371 | node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370) | Debian_linux, Connect | N/A | ||
2019-12-11 | CVE-2013-7370 | node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware | Debian_linux, Opensuse, Openshift, Connect | N/A | ||
2019-12-11 | CVE-2013-4158 | smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) | Debian_linux, Fedora, Smokeping | N/A | ||
2019-12-10 | CVE-2013-4133 | kde-workspace before 4.10.5 has a memory leak in plasma desktop | Debian_linux, Kde\-Workspace | N/A | ||
2019-11-27 | CVE-2012-6655 | An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords. | Accountsservice, Debian_linux, Opensuse, Enterprise_linux | N/A | ||
2019-12-10 | CVE-2012-1577 | lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0. | Debian_linux, Dietlibc, Openbsd | N/A | ||
2019-11-26 | CVE-2011-4120 | Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string. | Debian_linux, Pam_module | N/A | ||
2019-12-02 | CVE-2012-4428 | openslp: SLPIntersectStringList()' Function has a DoS vulnerability | Ubuntu_linux, Debian_linux, Fedora, Openslp | N/A |