Search

Found 1,351 results in 182ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2010-1451 low 2.1 FIX linux-kerneldebian debian 16y ago The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently…
CVE-2010-1161 low 3.7 FIX debian debian gnu 16y ago Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related…
CVE-2010-1160 low 1.9 FIX debian debian gnu 16y ago GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a …
CVE-2010-0750 low 2.1 FIX debian debian freedesktop 16y ago pkexec.c in pkexec in libpolkit in PolicyKit 0.96 allows local users to determine the existence of arbitrary files via the argument.
CVE-2010-0826 low 1.9 FIX debian debian piotr_roszatycki 16y ago The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information…
CVE-2010-0926 low 4.5 EXPFIX debian debian samba 17y ago The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traver…
CVE-2009-4664 low 3.3 FIX debian debian linux-kernel fwbuilder 17y ago Firewall Builder 3.0.4, 3.0.5, and 3.0.6, when running on Linux, allows local users to gain privileges via a symlink attack on an unspecified temporary file that is created by the iptables script.
CVE-2010-0789 low 3.3 FIX debian debian fuse 17y ago fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.
CVE-2009-4652 low 2.6 FIX debian debian ngircd 17y ago The (1) Conn_GetCipherInfo and (2) Conn_UsesSSL functions in src/ngircd/conn.c in ngIRCd 13 and 14, when SSL/TLS support is present and standalone mode is disabled, allow remote attackers to cause a …
CVE-2010-0424 low 3.3 FIX debian debian fedorahostedpaul_vixie 17y ago The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial o…
CVE-2003-1581 low 2.6 debian debian apache 17y ago The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafte…
CVE-2010-0547 low 2.1 FIX debian debian samba 17y ago client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to…
CVE-2010-0384 low 2.1 FIX debian debian tor 17y ago Tor 0.2.2.x before 0.2.2.7-alpha, when functioning as a directory mirror, does not prevent logging of the client IP address upon detection of erroneous client behavior, which might make it easier for…
CVE-2008-5161 low 3.7 4.7 EXPFIX debian debian openbsdssh 18y ago Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.…
CVE-2025-48708 low 2.5 FIX arch archdebian debian sles gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
CVE-2025-4575 low 2.5 FIX arch arch slesdebian debian Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certific…
CVE-2025-0620 low 2.5 FIX arch arch slesdebian debian A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect …
CVE-2022-27227 low 2.5 FIX arch arch slesdebian debian In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an…
CVE-2021-42917 low 2.5 FIX arch archdebian debian Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper length of values passed to istream.
CVE-2021-4110 low 2.5 FIX arch archdebian debian mruby is vulnerable to NULL Pointer Dereference
CVE-2021-40985 low 2.5 FIX arch arch slesdebian debian A stack-based buffer under-read in htmldoc before 1.9.12, allows attackers to cause a denial of service via a crafted BMP image to image_load_bmp.
CVE-2021-4069 low 2.5 FIX arch arch slesdebian debian vim is vulnerable to Use After Free
CVE-2021-4023 low 2.5 FIX arch arch slesdebian debian A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-urin…
CVE-2021-4021 low 2.5 FIX arch archdebian debian A vulnerability was found in Radare2 in versions prior to 5.6.2, 5.6.0, 5.5.4 and 5.5.2. Mapping a huge section filled with zeros of an ELF64 binary for MIPS architecture can lead to uncontrolled res…
CVE-2021-39929 low 2.5 FIX arch arch slesdebian debian Uncontrolled Recursion in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-39928 low 2.5 FIX arch arch slesdebian debian NULL pointer exception in the IEEE 802.11 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-39926 low 2.5 FIX arch arch slesdebian debian Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
CVE-2021-39925 low 2.5 FIX arch arch slesdebian debian Buffer overflow in the Bluetooth SDP dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-39924 low 2.5 FIX arch arch slesdebian debian Large loop in the Bluetooth DHT dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-39922 low 2.5 FIX arch arch slesdebian debian Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-39921 low 2.5 FIX arch arch slesdebian debian NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
CVE-2021-39920 low 2.5 FIX arch arch slesdebian debian NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
CVE-2021-3974 low 2.5 FIX arch arch slesdebian debian vim is vulnerable to Use After Free
CVE-2021-3973 low 2.5 FIX arch archdebian debian vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3968 low 2.5 FIX arch archdebian debian vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3928 low 2.5 FIX arch arch slesdebian debian vim is vulnerable to Use of Uninitialized Variable
CVE-2021-3927 low 2.5 FIX arch arch slesdebian debian vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-39247 low 2.5 FIX arch archdebian debian Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs_encode_uint in reedsol.c.
CVE-2021-3875 low 2.5 FIX arch arch slesdebian debian vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-38604 low 2.5 FIX arch arch slesdebian debian In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was…
CVE-2021-38373 low 2.5 FIX arch arch slesdebian debian In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked.
CVE-2021-37623 low 2.5 FIX arch archdebian debian sles Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini…
CVE-2021-37622 low 2.5 FIX arch archdebian debian sles Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini…
CVE-2021-37621 low 2.5 FIX arch archdebian debian sles Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infini…
CVE-2021-37620 low 2.5 FIX arch archdebian debian sles Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The o…
CVE-2021-37616 low 2.5 FIX arch archdebian debian sles Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. …
CVE-2021-37615 low 2.5 FIX arch archdebian debian sles Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. …
CVE-2021-36769 low 2.5 FIX arch archdebian debian content spoofing in telegram-desktop
CVE-2021-3673 low 2.5 FIX arch archdebian debian A vulnerability was found in Radare2 in version 5.3.1. Improper input validation when reading a crafted LE binary can lead to resource exhaustion and DoS.
CVE-2021-3671 low 2.5 FIX arch arch slesdebian debian A null pointer de-reference was found in the way samba kerberos server handled missing sname in TGS-REQ (Ticket Granting Server - Request). An authenticated user could use this flaw to crash the samb…
CVE-2021-36690 low 2.5 FIX arch arch slesdebian debian A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance o…
CVE-2021-3658 low 2.5 FIX debian debianarch arch sles bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discov…
CVE-2021-36367 low 2.5 FIX arch archdebian debian PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication response. This makes it easier for an attacker-controlled SSH server to present a l…
CVE-2021-3549 low 2.5 FIX debian debianarch arch sles An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a…
CVE-2021-35331 low 2.5 FIX arch archdebian debian In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple third parties dispute the significance of this finding
CVE-2021-34813 low 2.5 FIX arch archdebian debian Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has …
CVE-2021-3479 low 2.5 FIX arch arch slesdebian debian There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger excessive consumption o…
CVE-2021-3478 low 2.5 FIX arch arch slesdebian debian There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit a crafted file to be processed by OpenEXR could consume excessive system memory…
CVE-2021-3477 low 2.5 FIX arch arch slesdebian debian There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to be processed by OpenEXR could trigger an integer over…
CVE-2021-3476 low 2.5 FIX arch arch slesdebian debian A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to submit a crafted file to OpenEXR could trigger shift overflows, potentially aff…
CVE-2021-3475 low 2.5 FIX arch arch slesdebian debian There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by OpenEXR could cause an integer overflow, potentially leading to problems with ap…
CVE-2021-3474 low 2.5 FIX arch arch slesdebian debian There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a shift overflow in the FastHufDecoder, potentially leading to problems with app…
CVE-2021-34335 low 2.5 FIX arch archdebian debian sles Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A floating point exception (FPE) due to an integer divide by zero was found …
CVE-2021-34334 low 2.5 FIX arch arch slesdebian debian Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop is triggered when Exiv2 is used to read the metadata of a c…
CVE-2021-33500 low 2.5 FIX arch archdebian debian PuTTY before 0.75 on Windows allows remote servers to cause a denial of service (Windows GUI hang) by telling the PuTTY window to change its title repeatedly at high speed, which results in many SetW…
CVE-2021-32815 low 2.5 FIX arch arch slesdebian debian Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata…
CVE-2021-32719 low 2.5 FIX arch arch slesdebian debian cross-site scripting in rabbitmq
CVE-2021-32718 low 2.5 FIX arch arch slesdebian debian cross-site scripting in rabbitmq
CVE-2021-32613 low 2.5 FIX arch archdebian debian In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
CVE-2021-32275 low 2.5 arch archdebian debian An issue was discovered in faust through v2.30.5. A NULL pointer dereference exists in the function CosPrim::computeSigOutput() located in cosprim.hh. It allows an attacker to cause Denial of Service.
CVE-2021-31855 low 2.5 FIX arch archdebian debian KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g., an IMAP server) caus…
CVE-2021-3178 low 2.5 FIX arch arch slesdebian debian fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPL…
CVE-2021-30178 low 2.5 FIX arch arch slesdebian debian An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer dereference for certain accesses to the SynIC Hyper-V context, aka CID-919f4ebc5987.
CVE-2021-28831 low 2.5 FIX debian debianarch arch sles decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
CVE-2021-28117 low 2.5 FIX arch archdebian debian libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially dangerous URLs (that are neither https:// nor http://) based on the content of…
CVE-2021-28090 low 2.5 FIX arch archdebian debian Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
CVE-2021-28089 low 2.5 FIX arch archdebian debian Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
CVE-2021-28039 low 2.5 FIX arch arch slesdebian debian An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of…
CVE-2021-27815 low 2.5 FIX arch arch slesdebian debian NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicio…
CVE-2021-27212 low 2.5 FIX arch arch slesdebian debian In OpenLDAP through 2.4.57 and 2.5.x through 2.5.1alpha, an assertion failure in slapd can occur in the issuerAndThisUpdateCheck function via a crafted packet, resulting in a denial of service (daemo…
CVE-2021-26934 low 2.5 FIX arch arch slesdebian debian An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration…
CVE-2021-22235 low 2.5 FIX arch arch slesdebian debian Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file
CVE-2021-22222 low 2.5 FIX arch archdebian debian Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file
CVE-2021-22207 low 2.5 FIX arch arch slesdebian debian Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
CVE-2021-22174 low 2.5 FIX arch arch slesdebian debian Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
CVE-2021-22173 low 2.5 FIX arch arch slesdebian debian Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
CVE-2021-21300 low 3.5 EXPFIX arch arch slesdebian debian Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as…
CVE-2021-20296 low 2.5 FIX arch arch slesdebian debian A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is processed by the Dwa decompression functionality of OpenEXR's IlmImf library, could ca…
CVE-2021-20217 low 2.5 FIX arch archdebian debian A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system a…
CVE-2021-20216 low 2.5 FIX arch archdebian debian A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is t…
CVE-2021-20205 low 2.5 FIX arch archdebian debian Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.
CVE-2021-20193 low 2.5 FIX arch arch slesdebian debian A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input file to tar to cause uncontrolled consumption of memory. The highest threat fro…
CVE-2021-20177 low 2.5 FIX arch arch slesdebian debian A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root or CAP_NET_ADMIN) when inserting iptables rules could insert a rule which can pa…
CVE-2021-1405 low 2.5 FIX arch archdebian debian sles A vulnerability in the email parsing module in Clam AntiVirus (ClamAV) Software version 0.103.1 and all prior versions could allow an unauthenticated, remote attacker to cause a denial of service con…
CVE-2021-1404 low 2.5 FIX arch archdebian debian sles A vulnerability in the PDF parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service condition on an…
CVE-2021-1252 low 2.5 FIX arch archdebian debian sles A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software versions 0.103.0 and 0.103.1 could allow an unauthenticated, remote attacker to cause a denial of service con…
CVE-2020-9359 low 2.5 FIX arch arch slesdebian debian KDE Okular before 1.10.0 allows code execution via an action link in a PDF document.
CVE-2020-35501 low 2.5 arch arch slesdebian debian A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem
CVE-2020-35450 low 2.5 FIX arch archdebian debian Gobby 0.4.11 allows a NULL pointer dereference in the D-Bus handler for certain set_language calls.
CVE-2020-35112 low 2.5 FIX arch arch slesdebian debian If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an …