Skip to main content

Vendor archive

debian CVEs

Beta · best-effort

10,153 CVEs tagged to vendor debian1,088 Critical, 4,160 High, 4,456 Medium, 447 Low, 2 Unrated.

CVE-2005-0159

Published Apr 27, 2005

The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1001

Published Mar 1, 2005

Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1052

Published Mar 1, 2005

Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that cont…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2005-0624

Published Feb 28, 2005

reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0625

Published Feb 28, 2005

reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2005-0107

Published Feb 25, 2005

bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0964

Published Feb 9, 2005

Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-0888

Published Jan 27, 2005

Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cra…

CVSS 10.0 · Critical
Showing 9,976-10,000 of 10,153 CVEsPage 400 of 407