Search CVE reports


Toggle filters

401 – 410 of 553 results


CVE-2012-6140

Medium priority
Ignored

pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret...

1 affected package

google-authenticator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
google-authenticator
Show less packages

CVE-2012-5573

Medium priority
Ignored

The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-1189

Medium priority
Ignored

Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an...

1 affected package

torcs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torcs
Show less packages

CVE-2012-4922

Medium priority

Some fixes available 10 of 14

The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-4419

Low priority

Some fixes available 10 of 14

The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-3519

Medium priority

Some fixes available 10 of 14

routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection via a timing...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-3518

Low priority

Some fixes available 10 of 14

The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-3517

Medium priority

Some fixes available 10 of 14

Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-4000

Medium priority

Some fixes available 3 of 5

Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject...

1 affected package

fckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fckeditor
Show less packages

CVE-2012-1147

Low priority
Ignored

readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.

40 affected packages

apache2, apr-util, audacity, ayttm, cableswig...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 Ignored
apr-util Ignored
audacity Not affected
ayttm Not in release
cableswig Not in release
cadaver Not affected
celementtree Not in release
cmake Ignored
coin3 Not affected
expat Not affected
gdcm Not affected
ghostscript Ignored
grmonitor Not in release
insighttoolkit Not in release
kompozer Not in release
libparagui1.1 Not in release
matanza Not affected
paraview Not affected
poco Not affected
python-xml Not in release
python2.4 Not in release
python2.5 Not in release
python2.6 Not in release
simgear Not affected
sitecopy Not affected
smart Ignored
swish-e Not affected
tdom Not affected
texlive-bin Ignored
tla Not affected
vnc4 Ignored
vtk Not in release
w3c-libwww Not in release
wbxml2 Not affected
wxwidgets2.6 Not in release
wxwidgets2.8 Not in release
wxwindows2.4 Not in release
xmlrpc-c Ignored
xotcl Not affected
xulrunner Not in release
Show all 40 packages Show less packages