Search

Found 2,955 results in 609ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2022-25235 high 8.0 FIX rheldebian debian sles 4y ago Swish-e vulnerabilities
CVE-2015-2317 medium 4.3 FIX fedora fedoradebian debianubuntu ubuntu djangoproject 4y ago The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to c…
CVE-2012-1988 medium 6.0 FIX ubuntu ubuntudebian debianfedora fedora puppet 4y ago Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-crea…
CVE-2015-7529 high 7.8 7.8 FIX rhelubuntu ubuntudebian debian sos_project 4y ago sosreport in SoS 3.x allows local users to obtain sensitive information from sosreport files or gain privileges via a symlink attack on an archive file in a temporary directory, as demonstrated by so…
CVE-2017-5936 high 7.5 7.5 ubuntu ubuntu openstack 4y ago OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restriction…
CVE-2021-45930 medium 5.5 FIX slesdebian debian rhel 4y ago QtSvg vulnerabilities
CVE-2022-0492 high 7.8 10.0 KEVEXPFIX sles rockydebian debian redhatnetapp 4y ago Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
CVE-2022-25236 high 8.0 FIX debian debian sles rocky 4y ago Swish-e vulnerabilities
CVE-2022-0536 unknown FIX debian debianubuntu ubuntu 4y ago follow-redirects vulnerabilities
CVE-2022-0155 unknown FIX debian debianubuntu ubuntu 5y ago follow-redirects vulnerabilities
CVE-2021-3481 medium 5.5 FIX arch arch sles rocky 5y ago QtSvg vulnerabilities
CVE-2019-16168 medium 6.5 6.5 FIX rocky slesdebian debian sqlitenetapptenable 5y ago RHSA-2021:1968: mingw packages security and bug fix update (Moderate)
CVE-2020-29372 medium 4.7 4.7 FIX slesdebian debian linux-kernel 6y ago An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1…
CVE-2020-26237 unknown FIX debian debianubuntu ubuntu 6y ago Highlight.js vulnerability
CVE-2018-19869 medium 5.5 FIX sles rockydebian debian 6y ago QtSvg vulnerabilities
CVE-2019-11135 medium 6.5 6.5 FIX arch arch slesdebian debian slackwarehpintel 6y ago TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
CVE-2019-17571 critical 9.8 9.8 FIX debian debian slesubuntu ubuntu apachenetapporacle 7y ago Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization ga…
CVE-2019-13117 medium 5.3 5.3 FIX slesdebian debianubuntu ubuntu xmlsoftoracle 7y ago In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte o…
CVE-2019-11068 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu xmlsoftoraclenetapp 7y ago RHSA-2020:4464: libxslt security update (Moderate)
CVE-2019-10648 unknown FIX debian debianubuntu ubuntu 7y ago Robocode vulnerabilities
CVE-2019-7317 medium 5.3 5.3 FIX arch arch slesdebian debian libpngoraclehp 7y ago png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
CVE-2019-6109 medium 6.8 6.8 FIX arch arch slesubuntu ubuntu openbsdwinscpnetapp 7y ago An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the…
CVE-2018-17175 unknown FIX debian debianubuntu ubuntu 8y ago Python marshmallow vulnerabilities
CVE-2018-17958 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu qemuredhat 8y ago Qemu has a Buffer Overflow in rtl8139_do_receive in hw/net/rtl8139.c because an incorrect integer data type is used.
CVE-2018-13785 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu libpngoracle 8y ago In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG fil…
CVE-2018-3639 medium 5.5 6.5 EXPFIX slesdebian debian rhel intelarmredhat 8y ago Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of i…
CVE-2016-10708 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu openbsdnetapp 9y ago sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, relat…
CVE-2017-5753 medium 5.6 6.6 EXPFIX arch arch slesdebian debian inteloraclesynology 9y ago Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
CVE-2017-7160 high 8.8 8.8 FIX slesubuntu ubuntumacos macos apple 9y ago An issue was discovered in certain Apple products. iOS before 11.2 is affected. Safari before 11.0.2 is affected. iCloud before 7.2 on Windows is affected. iTunes before 12.7.2 on Windows is affected…
CVE-2017-17934 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick 7.0.7-17 Q16 x86_64 has memory leaks in coders/msl.c, related to MSLPopImage and ProcessMSLScript, and associated with mishandling of MSLPushImage calls.
CVE-2017-17914 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-16 Q16, a vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service (ReadOneMNGImage large loop) via a crafted …
CVE-2017-17887 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function GetImagePixelCache in magick/cache.c, which allows attackers to cause a denial of service via a crafted MNG image fi…
CVE-2017-17886 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadPSDChannelZip in coders/psd.c, which allows attackers to cause a denial of service via a crafted psd image file.
CVE-2017-17885 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadPICTImage in coders/pict.c, which allows attackers to cause a denial of service via a crafted PICT image file.
CVE-2017-17884 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-16 Q16, a memory leak vulnerability was found in the function WriteOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted PNG image file.
CVE-2017-17882 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadXPMImage in coders/xpm.c, which allows attackers to cause a denial of service via a crafted XPM image file.
CVE-2017-17881 medium 6.5 6.5 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted MAT image file.
CVE-2017-17879 high 8.8 8.8 FIX debian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGImage in coders/png.c, related to length calculation and caused by an off-by-one error.
CVE-2017-16995 high 7.8 8.8 EXPFIX arch archdebian debian linux-kernel 9y ago The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by lev…
CVE-2017-17820 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_list_one_macro in asm/preproc.c that will lead to a remote denial of service attack, related to mishandling of operand-type errors.
CVE-2017-17819 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in the function find_cc() in asm/preproc.c that will cause a remote denial of service attack, because pointers associated with …
CVE-2017-17818 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read that will cause a remote denial of service attack, related to a while loop in paste_tokens in asm/preproc.c.
CVE-2017-17817 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_verror in asm/preproc.c that will cause a remote denial of service attack.
CVE-2017-17816 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in pp_getline in asm/preproc.c that will cause a remote denial of service attack.
CVE-2017-17815 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is an illegal address access in is_mmacro() in asm/preproc.c that will cause a remote denial of service attack, because of a missing check for the relations…
CVE-2017-17814 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in do_directive in asm/preproc.c that will cause a remote denial of service attack.
CVE-2017-17813 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a use-after-free in the pp_list_one_macro function in asm/preproc.c that will cause a remote denial of service attack, related to mishandling of line-syn…
CVE-2017-17812 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer over-read in the function detoken() in asm/preproc.c that will cause a remote denial of service attack.
CVE-2017-17811 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a heap-based buffer overflow that will cause a remote denial of service attack, related to a strcpy in paste_tokens in asm/preproc.c, a similar issue to …
CVE-2017-17810 medium 5.5 5.5 FIX slesubuntu ubuntudebian debian nasm 9y ago In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unknown address" that will cause a remote denial of service attack, because asm/preproc.c mishandles macro calls that have the wrong number of…
CVE-2017-17806 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_A…
CVE-2017-17805 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYP…
CVE-2017-17789 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.
CVE-2017-17788 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.
CVE-2017-17787 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
CVE-2017-17786 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
CVE-2017-17785 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
CVE-2017-17784 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu gimp 9y ago In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
CVE-2017-17682 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-12 Q16, a large loop vulnerability was found in the function ExtractPostscript in coders/wpg.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted…
CVE-2017-17681 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-12 Q16, an infinite loop vulnerability was found in the function ReadPSDChannelZip in coders/psd.c, which allows attackers to cause a denial of service (CPU exhaustion) via a cra…
CVE-2017-17680 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago In ImageMagick 7.0.7-12 Q16, a memory leak vulnerability was found in the function ReadXPMImage in coders/xpm.c, which allows attackers to cause a denial of service via a crafted xpm image file.
CVE-2017-17669 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu exiv2 9y ago There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exiv2 0.26. A crafted PNG file will lead to a remote denial of service attack.
CVE-2017-1000407 high 7.4 7.4 FIX slesarch archdebian debian redhat 9y ago The Linux Kernel 2.6.32 and later are affected by a denial of service, by flooding the diagnostic port 0x80 an exception can be triggered leading to a kernel panic.
CVE-2017-17504 medium 6.5 6.5 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted file, related to ReadOneMNGImage.
CVE-2017-17499 critical 9.8 9.8 FIX debian debianubuntu ubuntu imagemagick 9y ago ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp.
CVE-2017-17480 critical 9.8 9.8 FIX slesdebian debianubuntu ubuntu uclouvain 9y ago In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of serv…
CVE-2017-13168 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 9y ago An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.
CVE-2017-15868 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu 9y ago The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a craf…
CVE-2016-1255 high 7.8 7.8 FIX slesdebian debianubuntu ubuntu debian 9y ago The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+deb8u2, in Debian unstable before 178, in Ubuntu 12.04 LTS before 129ubuntu1.2, i…
CVE-2016-1252 medium 5.9 6.9 EXPFIX debian debianubuntu ubuntu debian 9y ago The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1ubuntu2.17, in Ubuntu 16.04 LTS before 1.2.15ubuntu0.2, and in Ubuntu 16.10 bef…
CVE-2017-16612 high 7.5 7.5 FIX arch arch slesdebian debian x 9y ago libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with programs like GIMP. It is also possible that an attack ve…
CVE-2017-16611 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu x 9y ago In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as root, triggering tape rewinds, watchdogs, or similar mechanisms that can be trigge…
CVE-2017-17087 medium 5.5 5.5 FIX slesdebian debianubuntu ubuntu vim 9y ago fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local user…
CVE-2017-15275 high 7.5 7.5 FIX arch arch slesdebian debian samba 9y ago Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to clear allocated heap memory.
CVE-2017-14746 critical 9.8 9.8 FIX arch arch slesdebian debian samba 9y ago Use-after-free vulnerability in Samba 4.x before 4.7.3 allows remote attackers to execute arbitrary code via a crafted SMB1 request.
CVE-2017-14176 high 8.8 8.8 FIX debian debian slesubuntu ubuntu canonical 9y ago Bazaar through 2.7.0, when Subprocess SSH is used, allows remote attackers to execute arbitrary commands via a bzr+ssh URL with an initial dash character in the hostname, a related issue to CVE-2017-…
CVE-2017-16544 high 8.8 8.8 FIX arch archdebian debian sles busybox 9y ago In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and res…
CVE-2017-16845 critical 10.0 10.0 FIX slesdebian debianubuntu ubuntu qemu 9y ago hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.
CVE-2017-15115 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of…
CVE-2017-15102 medium 6.3 6.3 FIX slesdebian debian linux-kernel 9y ago The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by…
CVE-2017-8806 medium 5.5 5.5 FIX debian debianubuntu ubuntu postgresql 9y ago The Debian pg_ctlcluster, pg_createcluster, and pg_upgradecluster scripts, as distributed in the Debian postgresql-common package before 181+deb9u1 for PostgreSQL (and other packages related to Debia…
CVE-2017-16642 high 7.5 8.5 EXP slesdebian debianubuntu ubuntu phpnetapp 9y ago In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back of' directives could be used by attackers able to …
CVE-2017-16548 critical 9.8 9.8 FIX arch arch slesdebian debian samba 9y ago The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allows remote attackers to cause a denial of service (…
CVE-2017-16546 high 8.8 8.8 FIX slesdebian debianubuntu ubuntu imagemagick 9y ago The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uni…
CVE-2017-16533 medium 6.6 6.6 FIX arch arch slesdebian debian 9y ago The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have uns…
CVE-2017-16532 medium 6.6 6.6 FIX arch arch slesdebian debian 9y ago The get_endpoints function in drivers/usb/misc/usbtest.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly ha…
CVE-2017-16529 medium 6.6 6.6 FIX arch arch slesdebian debian 9y ago The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspec…
CVE-2017-16528 medium 6.6 6.6 FIX arch arch slesdebian debian 9y ago sound/core/seq_device.c in the Linux kernel before 4.13.4 allows local users to cause a denial of service (snd_rawmidi_dev_seq_free use-after-free and system crash) or possibly have unspecified other…
CVE-2017-16527 medium 6.6 6.6 FIX arch arch slesdebian debian 9y ago sound/usb/mixer.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (snd_usb_mixer_interrupt use-after-free and system crash) or possibly have unspecified other impact…
CVE-2017-16526 high 7.8 7.8 FIX arch arch slesdebian debian 9y ago drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafte…
CVE-2017-16525 medium 6.6 6.6 FIX arch arch slesdebian debian 9y ago The usb_serial_console_disconnect function in drivers/usb/serial/console.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (use-after-free and system crash) or possi…
CVE-2017-15908 high 7.5 7.5 FIX slesubuntu ubuntudebian debian systemd_project 9y ago In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-re…
CVE-2017-15873 medium 5.5 5.5 FIX debian debian slesubuntu ubuntu busybox 9y ago The get_next_block function in archival/libarchive/decompress_bunzip2.c in BusyBox 1.27.2 has an Integer Overflow that may lead to a write access violation.
CVE-2013-3567 high 7.5 FIX slesubuntu ubuntususe suse puppetpuppetlabs 9y ago Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arb…
CVE-2012-3867 medium 4.3 FIX ubuntu ubuntususe susedebian debian puppetpuppetlabs 9y ago lib/puppet/ssl/certificate_authority.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, does not properly restrict the characters in the Common Name field of a Ce…
CVE-2017-13088 medium 5.3 5.3 FIX arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response fra…
CVE-2017-13087 medium 5.3 5.3 FIX arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowin…
CVE-2017-13086 medium 6.8 6.8 FIX arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decry…
CVE-2017-13084 medium 6.8 6.8 arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, …
CVE-2017-13082 high 8.1 8.1 FIX arch arch slesubuntu ubuntu w1.fi 9y ago Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing …