Search

Found 1,351 results in 143ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2011-4623 low 2.1 FIX debian debian rsyslog 14y ago Integer overflow in the rsCStrExtendBuf function in runtime/stringbuf.c in the imfile module in rsyslog 4.x before 4.6.6, 5.x before 5.7.4, and 6.x before 6.1.4 allows local users to cause a denial o…
CVE-2012-4929 low 2.6 FIX debian debian googlemozilla 14y ago The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which…
CVE-2012-4422 low 3.5 FIX debian debian wordpress 14y ago wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature is enabled, does not check for network-administrator privileges before performing a network-wide activation of an installed …
CVE-2010-4819 low 3.6 FIX debian debian x 14y ago The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (serve…
CVE-2012-3380 low 2.1 FIX debian debian wargio 14y ago Directory traversal vulnerability in naxsi-ui/nx_extract.py in the Naxsi module before 0.46-1 for Nginx allows local users to read arbitrary files via unspecified vectors.
CVE-2012-3378 low 3.3 FIX debian debian gnome 14y ago The register_application function in atk-adaptor/bridge.c in GNOME at-spi2-atk 2.5.2 does not seed the random number generator and generates predictable temporary file names, which makes it easier fo…
CVE-2012-2658 low 2.1 FIX debian debian unixodbc 14y ago Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (crash) via a long string in the DRIVER option. NOTE: this issue might not be a vuln…
CVE-2012-2657 low 2.1 FIX debian debian unixodbc 14y ago Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this iss…
CVE-2012-4600 low 3.6 EXPFIX debian debian otrs 14y ago Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.14, 3.0.x before 3.0.16, and 3.1.x before 3.1.10, when Firefox or Opera is used, allows remote…
CVE-2012-1586 low 3.1 EXPFIX debian debian debian 14y ago mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error messag…
CVE-2011-4944 low 1.9 FIX slesdebian debian python 14y ago Python 2.6 through 3.2 creates ~/.pypirc with world-readable permissions before changing them after data has been written, which introduces a race condition that allows local users to obtain a userna…
CVE-2012-2103 low 1.2 FIX debian debian munin-monitoring 14y ago The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.
CVE-2012-3507 low 2.6 FIX debian debian roundcube 14y ago Cross-site scripting (XSS) vulnerability in program/steps/mail/func.inc in RoundCube Webmail before 0.8.0, when using the Larry skin, allows remote attackers to inject arbitrary web script or HTML vi…
CVE-2012-2687 low 2.6 FIX debian debian apache 14y ago Multiple cross-site scripting (XSS) vulnerabilities in the make_variant_list function in mod_negotiation.c in the mod_negotiation module in the Apache HTTP Server 2.4.x before 2.4.3, when the MultiVi…
CVE-2012-4579 low 3.5 FIX debian debian phpmyadmin 14y ago phpMyAdmin Multiple XSS Vulnerabilities
CVE-2012-4345 low 3.5 FIX debian debian phpmyadmin 14y ago phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page
CVE-2012-0856 low 2.6 FIX debian debian ffmpeg 14y ago Heap-based buffer overflow in the MPV_frame_start function in libavcodec/mpegvideo.c in FFmpeg before 0.9.1, when the lowres option is enabled, allows remote attackers to cause a denial of service (a…
CVE-2012-4296 low 3.3 FIX suse susedebian debian wireshark 14y ago Buffer overflow in epan/dissectors/packet-rtps2.c in the RTPS2 dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of ser…
CVE-2012-4295 low 3.3 FIX debian debian wireshark 14y ago Array index error in the channelised_fill_sdh_g707_format function in epan/dissectors/packet-erf.c in the ERF dissector in Wireshark 1.8.x before 1.8.2 might allow remote attackers to cause a denial …
CVE-2012-4293 low 3.3 FIX suse susedebian debian wireshark 14y ago plugins/ethercat/packet-ecatmb.c in the EtherCAT Mailbox dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly handle certain integer fields, which…
CVE-2012-4292 low 3.3 FIX suse susedebian debian wireshark 14y ago The dissect_stun_message function in epan/dissectors/packet-stun.c in the STUN dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 does not properly interact with …
CVE-2012-4291 low 3.3 FIX suse suse rheldebian debian wireshark 14y ago The CIP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
CVE-2012-4290 low 3.3 FIX suse suse rheldebian debian wireshark 14y ago The CTDB dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU consumption) via a malformed packet.
CVE-2012-4289 low 3.3 FIX suse suse rheldebian debian wireshark 14y ago epan/dissectors/packet-afp.c in the AFP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause a denial of service (loop and CPU cons…
CVE-2012-4288 low 3.3 FIX suse susedebian debian wireshark 14y ago Integer overflow in the dissect_xtp_ecntl function in epan/dissectors/packet-xtp.c in the XTP dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote att…
CVE-2012-4285 low 3.3 FIX suse suse rheldebian debian wireshark 14y ago The dissect_pft function in epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.4.x before 1.4.15, 1.6.x before 1.6.10, and 1.8.x before 1.8.2 allows remote attackers to cause …
CVE-2012-4037 low 2.6 FIX debian debian transmissionbt 14y ago Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or…
CVE-2012-2141 low 3.5 FIX debian debian net-snmp 14y ago Array index error in the handle_nsExtendOutput2Table function in agent/mibgroup/agent/extend.c in Net-SNMP 5.7.1 allows remote authenticated users to cause a denial of service (out-of-bounds read and…
CVE-2011-4922 low 2.1 FIX debian debian pidgin 14y ago cipher.c in the Cipher API in libpurple in Pidgin before 2.7.10 retains encryption-key data in process memory, which might allow local users to obtain sensitive information by reading a core file or …
CVE-2012-3445 low 3.5 FIX debian debian redhat 14y ago The virTypedParameterArrayClear function in libvirt 0.9.13 does not properly handle virDomain* API calls with typed parameters, which might allow remote authenticated users to cause a denial of servi…
CVE-2012-3453 low 3.6 FIX debian debian debian 14y ago logol 1.5.0 uses world writable permissions for the /var/lib/logol/results directory, which allows local users to delete or overwrite arbitrary files.
CVE-2012-3452 low 3.3 FIX debian debian gnome 14y ago gnome-screensaver 3.4.x before 3.4.4 and 3.5.x before 3.5.4, when multiple screens are used, only locks the screen with the active focus, which allows physically proximate attackers to bypass screen …
CVE-2012-3449 low 3.6 FIX debian debian openvswitch 14y ago Open vSwitch 1.4.2 uses world writable permissions for (1) /var/lib/openvswitch/pki/controllerca/incoming/ and (2) /var/lib/openvswitch/pki/switchca/incoming/, which allows local users to delete and …
CVE-2011-2503 low 3.7 FIX debian debian systemtap 14y ago The insert_module function in runtime/staprun/staprun_funcs.c in the systemtap runtime tool (staprun) in SystemTap before 1.6 does not properly validate a module when loading it, which allows local u…
CVE-2012-2760 low 3.1 EXPFIX debian debian findingscience 14y ago mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local users to obtain session ids.
CVE-2012-3954 low 3.3 FIX debian debianubuntu ubuntu isc 14y ago Multiple memory leaks in ISC DHCP 4.1.x and 4.2.x before 4.2.4-P1 and 4.1-ESV before 4.1-ESV-R6 allow remote attackers to cause a denial of service (memory consumption) by sending many requests.
CVE-2012-4049 low 2.9 FIX suse susedebian debian wireshark 14y ago epan/dissectors/packet-nfs.c in the NFS dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (loop and CPU consu…
CVE-2012-4048 low 3.3 FIX debian debian wireshark 14y ago The PPP dissector in Wireshark 1.4.x before 1.4.14, 1.6.x before 1.6.9, and 1.8.x before 1.8.1 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash)…
CVE-2012-3383 low 2.6 FIX debian debian wordpress 14y ago The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows…
CVE-2012-2737 low 1.9 FIX debian debian ray_stode 14y ago The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directo…
CVE-2011-3149 low 2.1 FIX debian debian linux-pam 14y ago The _expand_arg function in the pam_env module (modules/pam_env/pam_env.c) in Linux-PAM (aka pam) before 1.1.5 does not properly handle when environment variable expansion can overflow, which allows …
CVE-2012-3371 low 3.5 FIX debian debian openstack 14y ago The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authenticated users to cause a denial of servic…
CVE-2012-3355 low 3.6 FIX debian debian gnome 14y ago (1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack …
CVE-2012-1174 low 3.3 FIX debian debian 14y ago The rm_rf_children function in util.c in the systemd-logind login manager in systemd before 44, when logging out, allows local users to delete arbitrary files via a symlink attack on unspecified file…
CVE-2012-1620 low 3.6 FIX debian debian suckless 14y ago slock 0.9 does not properly handle the XRaiseWindow event when the screen is locked, which might allow physically proximate attackers to obtain sensitive information by pressing a button, which revea…
CVE-2012-3368 low 2.6 FIX debian debian redhat 14y ago Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an …
CVE-2012-2214 low 3.5 FIX debian debian pidgin 14y ago proxy.c in libpurple in Pidgin before 2.10.4 does not properly handle canceled SOCKS5 connection attempts, which allows user-assisted remote authenticated users to cause a denial of service (applicat…
CVE-2011-4029 low 2.9 EXPFIX debian debian x.org 14y ago The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to change the permissions of arbitrary files to 444, read those files, and possibly cause a denial of service (…
CVE-2011-4028 low 1.2 FIX debian debian x.org 14y ago The LockServer function in os/utils.c in X.Org xserver before 1.11.2 allows local users to determine the existence of arbitrary files via a symlink attack on a temporary lock file, which is handled d…
CVE-2012-2746 low 2.1 FIX debian debian redhatfedoraproject 14y ago 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), when the password of a LDAP user has been changed and audit logging is enabled, saves the new password to the log …
CVE-2012-2678 low 1.2 FIX debian debian redhatfedoraproject 14y ago 389 Directory Server before 1.2.11.6 (aka Red Hat Directory Server before 8.2.10-3), after the password for a LDAP user has been changed and before the server has been reset, allows remote attackers …
CVE-2012-0833 low 2.3 FIX debian debian fedoraproject 14y ago The acllas__handle_group_entry function in servers/plugins/acl/acllas.c in 389 Directory Server before 1.2.10 does not properly handled access control instructions (ACIs) that use certificate groups,…
CVE-2012-3826 low 4.3 EXPFIX debian debian wireshark 14y ago Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (loop) via vectors related to the R3 dissector, a different vul…
CVE-2012-3825 low 4.3 EXPFIX debian debian wireshark 14y ago Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) BACapp and (2) Bl…
CVE-2012-2394 low 4.3 EXPFIX debian debian wireshark 14y ago Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data alignment for a certain structure member, which allows remote attackers to cause…
CVE-2012-2393 low 4.3 EXPFIX debian debian wireshark 14y ago epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does not properly construct certain array data structures, which allows remote atta…
CVE-2012-2392 low 4.3 EXPFIX debian debian wireshark 14y ago Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop) via vectors related to the (1) ANSI MAP, (2) ASF, (3) IEEE 802.11, (4) IEEE 8…
CVE-2012-2690 low 2.1 FIX debian debian libguestfs 14y ago virt-edit in libguestfs before 1.18.0 does not preserve the permissions from the original file and saves the new file with world-readable permissions when editing, which might allow local guest users…
CVE-2012-1164 low 2.6 FIX debian debian openldap 14y ago slapd in OpenLDAP before 2.4.30 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an LDAP search query with attrsOnly set to true, which causes empty attrib…
CVE-2012-3818 low 2.1 FIX debian debian mikel_olasagasti 14y ago The fpm exporter in Revelation 0.4.13-2 and earlier encrypts the version number but not the password when exporting a file, which might allow local users to obtain sensitive information.
CVE-2012-2451 low 3.6 FIX debian debian shlomi_fish 14y ago The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these detai…
CVE-2011-4940 low 2.6 FIX debian debian python 14y ago The list_directory function in Lib/SimpleHTTPServer.py in SimpleHTTPServer in Python before 2.5.6c1, 2.6.x before 2.6.7 rc2, and 2.7.x before 2.7.2 does not place a charset parameter in the Content-T…
CVE-2012-2389 low 2.1 FIX debian debian w1.fi 14y ago hostapd 0.7.3, and possibly other versions before 1.0, uses 0644 permissions for /etc/hostapd/hostapd.conf, which might allow local users to obtain sensitive information such as credentials.
CVE-2012-3587 low 2.6 FIX debian debian debian 14y ago APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attacker…
CVE-2012-0954 low 2.6 FIX debian debian debian 14y ago APT 0.7.x before 0.7.25 and 0.8.x before 0.8.16, when using the apt-key net-update to import keyrings, relies on GnuPG argument order and does not check GPG subkeys, which might allow remote attacker…
CVE-2012-2693 low 3.7 FIX debian debian redhat 14y ago libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associate…
CVE-2012-2672 low 2.1 FIX debian debian oracle 14y ago Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by callin…
CVE-2012-2313 low 1.2 FIX debian debian linux-kernelsuse suse 14y ago The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet…
CVE-2012-2101 low 3.5 FIX debian debian openstack 14y ago Openstack Compute (Nova) Folsom, 2012.1, and 2011.3 does not limit the number of security group rules, which allows remote authenticated users with certain permissions to cause a denial of service (C…
CVE-2011-4459 low 3.5 FIX debian debian bestpractical 14y ago Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups, which allows remote authenticated users to bypass intended access restrictions in opportunistic ci…
CVE-2012-1253 low 2.6 FIX debian debian roundcube 14y ago Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 0.7, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via vectors involving an embed…
CVE-2012-2947 low 2.6 FIX debian debian digium 14y ago chan_iax2.c in the IAX2 channel driver in Certified Asterisk 1.8.11-cert before 1.8.11-cert2 and Asterisk Open Source 1.8.x before 1.8.12.1 and 10.x before 10.4.1, when a certain mohinterpret setting…
CVE-2012-1986 low 2.1 FIX debian debian puppetpuppetlabs 14y ago Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with an authorized SSL key and ce…
CVE-2012-1906 low 3.3 FIX debian debian puppetpuppetlabs 14y ago Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from …
CVE-2011-2722 low 1.2 FIX debian debian hp 14y ago The send_data_to_stdout function in prnt/hpijs/hpcupsfax.cpp in HP Linux Imaging and Printing (HPLIP) 3.x before 3.11.10 allows local users to overwrite arbitrary files via a symlink attack on the /t…
CVE-2012-2120 low 3.3 FIX debian debian debian 14y ago latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a te…
CVE-2012-2093 low 3.3 FIX debian debian gajim 14y ago src/common/latex.py in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink attack on a temporary latex file, related to the get_tmpfile_name function.
CVE-2012-0863 low 2.1 FIX debian debian mumble 14y ago Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext password and config…
CVE-2012-1594 low 3.3 FIX debian debian wireshark 14y ago epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
CVE-2012-1593 low 4.3 EXPFIX debian debian wireshark 14y ago epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark 1.4.x before 1.4.12 and 1.6.x before 1.6.6 allows remote attackers to cause a denial of service (NULL pointer dereference and appl…
CVE-2012-0042 low 2.9 FIX rheldebian debian wireshark 14y ago Wireshark 1.4.x before 1.4.11 and 1.6.x before 1.6.5 does not properly perform certain string conversions, which allows remote attackers to cause a denial of service (NULL pointer dereference and app…
CVE-2011-5000 low 3.5 FIX debian debian openbsd 14y ago The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory co…
CVE-2012-0808 low 3.6 FIX debian debian bdale_garbee 14y ago as31 2.3.1-4 does not seed the random number generator and generates predictable temporary file names, which makes it easier for local users to create or truncate files via a symlink attack.
CVE-2011-4105 low 1.9 FIX debian debian robert_ancell 15y ago LightDM before 1.0.6 allows local users to change ownership of arbitrary files via a symlink attack on ~/.Xauthority.
CVE-2012-0021 low 2.6 FIX debian debian apache 15y ago The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, w…
CVE-2012-0111 low 3.6 FIX debian debian oracle 15y ago Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization 4.1 allows local users to affect confidentiality and integrity via unknown vectors related to Shared Folders.
CVE-2012-0105 low 3.7 FIX debian debian oracle 15y ago Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization 4.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to W…
CVE-2011-5060 low 3.3 FIX debian debian roderich_schupp 15y ago The par_mktmpdir function in the PAR module before 1.003 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory, which a…
CVE-2011-4114 low 3.3 FIX debian debian roderich_schupp 15y ago The par_mktmpdir function in the PAR::Packer module before 1.012 for Perl creates temporary files in a directory with a predictable name without verifying ownership and permissions of this directory,…
CVE-2011-5056 low 2.1 FIX debian debian maradns 15y ago The authoritative server in MaraDNS through 2.0.04 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which might allow local users to cause a d…
CVE-2012-0287 low 2.6 FIX debian debian wordpressmicrosoft 15y ago Cross-site scripting (XSS) vulnerability in wp-comments-post.php in WordPress 3.3.x before 3.3.1, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via th…
CVE-2011-4606 low 3.6 FIX debian debian artsoft 15y ago Artsoft Entertainment Rocks'n'Diamonds (aka rocksndiamonds) 3.3.0.1 allows local users to overwrite arbitrary files via a symlink attack on .rocksndiamonds/cache/artworkinfo.cache under a user's home…
CVE-2011-4339 low 3.6 FIX debian debian rhel ipmitool_project 15y ago ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for…
CVE-2011-4345 low 2.6 FIX debian debian namazumicrosoft 15y ago Cross-site scripting (XSS) vulnerability in Namazu before 2.0.21, when Internet Explorer 6 or 7 is used, allows remote attackers to inject arbitrary web script or HTML via a cookie.
CVE-2011-4415 low 2.2 EXPFIX debian debian apache 15y ago The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when the mod_setenvif module is enabled, does not restrict the size of values of envi…
CVE-2011-3872 low 2.6 FIX debian debian puppetpuppetlabs 15y ago Puppet 2.6.x before 2.6.12 and 2.7.x before 2.7.6, and Puppet Enterprise (PE) Users 1.0, 1.1, and 1.2 before 1.2.4, when signing an agent certificate, adds the Puppet master's certdnsnames values to …
CVE-2011-1159 low 3.1 EXPFIX debian debian tedfelix 15y ago acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service …
CVE-2011-2724 low 1.2 FIX slesdebian debian samba 15y ago The check_mtab function in client/mount.cifs.c in mount.cifs in smbfs in Samba 3.5.10 and earlier does not properly verify that the (1) device name and (2) mountpoint strings are composed of valid ch…
CVE-2011-2176 low 2.1 FIX debian debian gnome 15y ago GNOME NetworkManager before 0.8.6 does not properly enforce the auth_admin element in PolicyKit, which allows local users to bypass intended wireless network sharing restrictions via unspecified vect…
CVE-2011-0543 low 3.3 FIX debian debian fuse 15y ago Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmo…