Skip to main content

Vendor/product archive

debian / linux CVEs

Beta · best-effort

8 CVEs tagged to debian / linux1 Critical, 0 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2011-1548

Published Mar 30, 2011

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, which allows local users to cond…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4338

Published Jan 20, 2011

ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR e…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4695

Published Jan 14, 2011

A certain Fedora patch for gif2png.c in gif2png 2.5.1 and 2.5.2, as distributed in gif2png-2.5.1-1200.fc12 on Fedora 12 and gif2png_2.5.2-1 on Debian GNU/Linux, truncates a GIF pa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2946

Published Sep 4, 2009

Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3831

Published Oct 20, 2008

The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD does not restrict the DRM_I915_HWS_…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2008-4126

Published Sep 18, 2008

PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4099

Published Sep 18, 2008

PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4109

Published Sep 18, 2008

A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functions that are not async-signal-s…

CVSS 5.0 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1