Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-12-13 | CVE-2014-3495 | duplicity 0.6.24 has improper verification of SSL certificates | Debian_linux, Duplicity, Opensuse | N/A | ||
2019-12-13 | CVE-2014-2387 | Pen 0.18.0 has Insecure Temporary File Creation vulnerabilities | Debian_linux, Opensuse, Pen | N/A | ||
2019-11-27 | CVE-2013-2625 | An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified | Debian_linux, Opensuse, Faq, Otrs_help_desk, Otrs_itsm | N/A | ||
2019-12-06 | CVE-2012-2130 | A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys. | Debian_linux, Fedora, Polarssl | N/A | ||
2019-12-05 | CVE-2012-1105 | An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client library archives the debug logging file in an insecure manner. | Phpcas, Debian_linux, Fedora | N/A | ||
2019-12-10 | CVE-2016-1000108 | yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. | Debian_linux, Yaws | N/A | ||
2019-11-29 | CVE-2015-1855 | verify_certificate_identity in the OpenSSL extension in Ruby before 2.0.0 patchlevel 645, 2.1.x before 2.1.6, and 2.2.x before 2.2.2 does not properly validate hostnames, which allows remote attackers to spoof servers via vectors related to (1) multiple wildcards, (1) wildcards in IDNA names, (3) case sensitivity, and (4) non-ASCII characters. | Debian_linux, Puppet_agent, Puppet_enterprise, Ruby, Trunk | N/A | ||
2019-12-11 | CVE-2013-7371 | node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370) | Debian_linux, Connect | N/A | ||
2019-12-11 | CVE-2013-7370 | node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware | Debian_linux, Opensuse, Openshift, Connect | N/A | ||
2019-12-11 | CVE-2013-4158 | smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790) | Debian_linux, Fedora, Smokeping | N/A |