VendorsDebiandebian_linux8.0
Vulnerabilities

Debian Debian Linux 8.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3484CVEs
CVE-2011-2726
An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attached to the comment if they know or guess its direct URL.
Published 2019-11-15 · Modified
7.5EPSS 0.016
CVE-2020-1772
Information Disclosure
Published 2020-03-27 · Modified
7.5EPSS 0.016
CVE-2020-11728
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.
Published 2020-04-15 · Modified
7.5EPSS 0.016
CVE-2013-2106
webauth before 4.6.1 has authentication credential disclosure
Published 2019-12-03 · Modified
7.5EPSS 0.016
CVE-2013-6646
Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the shutting down of a worker process.
Published 2014-01-16 · Modified
7.5EPSS 0.016
CVE-2015-1280
SkPictureShader.cpp in Skia, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging access to a renderer process and providing crafted serialized data.
Published 2015-07-23 · Modified
7.5EPSS 0.016
CVE-2015-1238
Skia, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via unknown vectors.
Published 2015-04-19 · Modified
7.5EPSS 0.016
CVE-2015-1262
platform/fonts/shaping/HarfBuzzShaper.cpp in Blink, as used in Google Chrome before 43.0.2357.65, does not initialize a certain width field, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted Unicode text.
Published 2015-05-20 · Modified
7.5EPSS 0.016
CVE-2018-10242
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.
Published 2019-04-04 · Modified
7.5EPSS 0.016
CVE-2010-4657
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
Published 2019-11-13 · Modified
7.5EPSS 0.015
CVE-2012-6111
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
Published 2019-12-20 · Modified
7.5EPSS 0.015
CVE-2018-10857
git-annex is vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN.
Published 2018-07-16 · Modified
7.5EPSS 0.015
CVE-2019-18602
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.
Published 2019-10-29 · Modified
7.5EPSS 0.015
CVE-2011-4931
gpw generates shorter passwords than required
Published 2019-10-29 · Modified
7.5EPSS 0.015
CVE-2018-10852
The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. This affects versions of SSSD before 1.16.3.
Published 2018-06-26 · Modified
7.5EPSS 0.015
CVE-2013-6649
Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a zero-size SVG image.
Published 2014-01-28 · Modified
7.5EPSS 0.014
CVE-2016-1691
Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoincidence.cpp and SkPathOpsCommon.cpp.
Published 2016-06-05 · Modified
7.5EPSS 0.014
CVE-2017-8819
In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, the replay-cache protection mechanism is ineffective for v2 onion services, aka TROVE-2017-009. An attacker can send many INTRODUCE2 cells to trigger this issue.
Published 2017-12-03 · Modified
7.5EPSS 0.014
CVE-2016-3163
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
Published 2016-04-12 · Modified
7.5EPSS 0.014
CVE-2017-6802
An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to DecompressRTF() in libytnef.
Published 2017-03-10 · Modified
7.5EPSS 0.014
CVE-2015-1259
PDFium, as used in Google Chrome before 43.0.2357.65, does not properly initialize memory, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Published 2015-05-20 · Modified
7.5EPSS 0.014
CVE-2018-5735
Backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858
Published 2019-10-30 · Modified
7.5EPSS 0.014
CVE-2019-11272
PlaintextPasswordEncoder authenticates encoded passwords that are null
Published 2019-06-26 · Analyzed
7.5EPSS 0.014
CVE-2018-1128
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access to ceph cluster network who is able to sniff packets on network can use this vulnerability to authenticate with ceph service and perform actions allowed by ceph service. Ceph branches master, mimic, luminous and jewel are believed to be vulnerable.
Published 2018-07-10 · Modified
7.5EPSS 0.014
CVE-2015-1249
Multiple unspecified vulnerabilities in Google Chrome before 42.0.2311.90 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Published 2015-04-19 · Modified
7.5EPSS 0.014
CVE-2018-10859
git-annex is vulnerable to an Information Exposure when decrypting files. A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could be used to expose encrypted data that was never stored in git-annex
Published 2018-07-16 · Modified
7.5EPSS 0.014
CVE-2015-5726
The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.
Published 2016-05-13 · Modified
7.5EPSS 0.014
CVE-2015-1289
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Published 2015-07-23 · Modified
7.5EPSS 0.013
CVE-2014-1936
rc before 1.7.1-5 insecurely creates temporary files.
Published 2019-11-21 · Modified
7.5EPSS 0.013
CVE-2012-6071
nuSOAP before 0.7.3-5 does not properly check the hostname of a cert.
Published 2019-11-19 · Modified
7.5EPSS 0.013
CVE-2011-0529
Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
Published 2019-11-20 · Modified
7.5EPSS 0.013
CVE-2010-5108
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
Published 2019-11-13 · Modified
7.5EPSS 0.013
CVE-2012-2350
pam_shield before 0.9.4: Default configuration does not perform protective action
Published 2019-11-21 · Modified
7.5EPSS 0.013
CVE-2017-12874
The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature validation utilities.
Published 2017-09-01 · Modified
7.5EPSS 0.013
CVE-2009-3723
asterisk allows calls on prohibited networks
Published 2019-10-29 · Modified
7.5EPSS 0.012
CVE-2020-5390
PySAML2 before 5.0.0 does not check that the signature in a SAML document is enveloped and thus signature wrapping is effective, i.e., it is affected by XML Signature Wrapping (XSW). The signature information and the node/object that is signed can be in different places and thus the signature verification will succeed, but the wrong data will be used. This specifically affects the verification of assertion that have been signed.
Published 2020-01-13 · Modified
7.5EPSS 0.012
CVE-2014-3167
Multiple unspecified vulnerabilities in Google Chrome before 36.0.1985.143 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
Published 2014-08-13 · Modified
7.5EPSS 0.012
CVE-2019-3813
Spice, versions 0.5.2 through 0.14.1, are vulnerable to an out-of-bounds read due to an off-by-one error in memslot_get_virt. This may lead to a denial of service, or, in the worst case, code-execution by unauthenticated attackers.
Published 2019-02-04 · Modified
7.5EPSS 0.012
CVE-2010-2450
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.
Published 2019-11-07 · Modified
7.5EPSS 0.012
CVE-2012-1572
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
Published 2019-11-12 · Modified
7.5EPSS 0.012
← Prev47 / 88Next →