Search: "debian"

239 CVEs found

Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers to cause a denial of service (crash) and possibly ...

Published: 2008-04-16
Products: 1
Vendors:
fireflymediaserver

OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to condu...

Published: 2008-05-13
Products: 6
Vendors:
debian canonical openssl
CVE-2008-3234
6.5 MEDIUM

sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, follow...

Published: 2008-07-18
Products: 2
Vendors:
openbsd debian
CVE-2008-4109
5.0 MEDIUM

A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-safe in the signal han...

Published: 2008-09-18
Products: 133
Vendors:
openbsd debian
CVE-2008-4099
6.4 MEDIUM

PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a dif...

Published: 2008-09-18
Products: 11
Vendors:
debian
CVE-2008-4126
6.4 MEDIUM

PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote at...

Published: 2008-09-18
Products: 12
Vendors:
debian

A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to delete or overwrite arbitrary files via a symlink attack on unspecified .tmp files.

Published: 2008-10-03
Products: 1
Vendors:
debian

qemu-make-debian-root in qemu 0.9.1-5 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files and directories.

Published: 2008-10-15
Products: 2
Vendors:
debian qemu
CVE-2008-3831
4.7 MEDIUM

The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD does not restrict the DRM_I915_HWS_ADDR ioctl to the Dir...

Published: 2008-10-20
Products: 3
Vendors:
openbsd debian linux
CVE-2008-5142
6.9 MEDIUM

sendbug in freebsd-sendpr 3.113+5.3 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pr.##### temporary file.

Published: 2008-11-18
Products: 1
Vendors:
freebsd
CVE-2008-5366
6.9 MEDIUM

The postinst script in ppp 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/probe-finished or (2) /tmp/ppp-errors temporary file.

Published: 2008-12-08
Products: 1
Vendors:
marco_d\'itri
CVE-2008-5367
6.9 MEDIUM

ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/resolv.conf.tmp temporary file.

Published: 2008-12-08
Products: 1
Vendors:
marco_d\'itri

/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file re...

Published: 2008-12-09
Products: 1
Vendors:
debian

Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for...

Published: 2008-12-29
Products: 8
Vendors:
debian canonical qemu kvm_qumranet

The default configuration of xterm on Debian GNU/Linux sid and possibly Ubuntu enables the allowWindowOps resource, which allows user-assisted attackers to execute arbitrary code or have unspecified o...

Published: 2009-01-02
Products: 3
Vendors:
debian ubuntu invisible-island
CVE-2009-1573
4.6 MEDIUM

xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing...

Published: 2009-05-06
Products: 4
Vendors:
debian branden_robinson ubuntu redhat
CVE-2009-1381
6.8 MEDIUM

The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbit...

Published: 2009-05-22
Products: 21
Vendors:
squirrelmail

Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source ...

Published: 2009-09-04
Products: 2
Vendors:
devscripts_devel_team debian

pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which cau...

Published: 2009-09-17
Products: 2
Vendors:
canonical
CVE-2009-2939
6.9 MEDIUM

The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink at...

Published: 2009-09-21
Products: 3
Vendors:
debian postfix ubuntu