Search CVE reports


Toggle filters

311 – 320 of 465 results


CVE-2013-1063

Medium priority

Some fixes available 3 of 4

usb-creator 0.2.47 before 0.2.47.1, 0.2.40 before 0.2.40ubuntu2, and 0.2.38 before 0.2.38.2 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by...

1 affected package

usb-creator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
usb-creator
Show less packages

CVE-2013-2099

Low priority

Some fixes available 5 of 41

Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote...

10 affected packages

bzr, w3af, linkchecker, python-tornado, python-urllib3...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bzr Not affected Not affected Not affected Not affected
w3af Not in release Not in release Not in release Not in release
linkchecker Not affected Not affected Not in release Not affected
python-tornado Not affected Not affected Not affected Not affected
python-urllib3 Not affected Not affected Not affected Not affected
python2.7 Not in release Not affected Not affected Not affected
python3.1 Not in release Not in release Not in release Not in release
python3.2 Not in release Not in release Not in release Not in release
python3.3 Not in release Not in release Not in release Not in release
zeroinstall-injector Not affected Not affected Not affected Not affected
Show all 10 packages Show less packages

CVE-2012-6140

Medium priority
Ignored

pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret...

1 affected package

google-authenticator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
google-authenticator
Show less packages

CVE-2012-5573

Medium priority
Ignored

The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-1189

Medium priority
Ignored

Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an...

1 affected package

torcs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torcs
Show less packages

CVE-2012-4922

Medium priority

Some fixes available 10 of 14

The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-4419

Low priority

Some fixes available 10 of 14

The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-3519

Medium priority

Some fixes available 10 of 14

routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection via a timing...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-3518

Low priority

Some fixes available 10 of 14

The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2012-3517

Medium priority

Some fixes available 10 of 14

Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages