Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Debian_linux
(Debian)Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2017-09-20 | CVE-2017-14604 | GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file actually has the potentially unsafe .desktop extension; instead, the UI only shows the .pdf extension. One (slightly) mitigating factor is that an attack requires the .desktop file... | Debian_linux, Nautilus | N/A | ||
2019-12-02 | CVE-2012-4576 | FreeBSD: Input Validation Flaw allows local users to gain elevated privileges | Debian_linux, Freebsd | N/A | ||
2019-11-26 | CVE-2011-4082 | A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain values of the "Accept-Language" HTTP header. A remote attacker could use this flaw to cause a denial of service via specially-crafted request. | Debian_linux, Phpldapadmin | N/A | ||
2019-11-26 | CVE-2011-3617 | Tahoe-LAFS v1.3.0 through v1.8.2 could allow unauthorized users to delete immutable files in some cases. | Debian_linux, Tahoe\-Lafs | N/A | ||
2019-12-04 | CVE-2013-2745 | An SQL Injection vulnerability exists in MiniDLNA prior to 1.1.0 | Debian_linux, Minidlna | N/A | ||
2019-12-03 | CVE-2013-2106 | webauth before 4.6.1 has authentication credential disclosure | Debian_linux, Webauth | N/A | ||
2019-11-25 | CVE-2012-5521 | quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal | Debian_linux, Quagga, Enterprise_linux | N/A | ||
2019-12-05 | CVE-2012-1115 | A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php. | Debian_linux, Fedora, Ldap_account_manager | N/A | ||
2019-11-26 | CVE-2011-1939 | SQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction PDO_MySql in PHP before 5.3.6. | Debian_linux, Php, Zend_framework | N/A | ||
2019-11-26 | CVE-2011-1934 | lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1. | Debian_linux, Lilo | N/A |