Search CVE reports


Toggle filters

401 – 410 of 553 results


CVE-2012-6140

Medium priority
Ignored

pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret...

1 affected package

google-authenticator

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
google-authenticator — — — — —
Show less packages

CVE-2012-5573

Medium priority
Ignored

The connection_edge_process_relay_cell function in or/relay.c in Tor before 0.2.3.25 maintains circuits even if an unexpected SENDME cell arrives, which might allow remote attackers to cause a denial of service (memory consumption...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2012-1189

Medium priority
Ignored

Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an...

1 affected package

torcs

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
torcs — — — — —
Show less packages

CVE-2012-4922

Medium priority

Some fixes available 10 of 14

The tor_timegm function in common/util.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.22-rc, does not properly validate time values, which allows remote attackers to cause a denial of service (assertion failure and daemon...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2012-4419

Low priority

Some fixes available 10 of 14

The compare_tor_addr_to_addr_policy function in or/policies.c in Tor before 0.2.2.39, and 0.2.3.x before 0.2.3.21-rc, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a zero-valued port...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2012-3519

Medium priority

Some fixes available 10 of 14

routerlist.c in Tor before 0.2.2.38 uses a different amount of time for relay-list iteration depending on which relay is chosen, which might allow remote attackers to obtain sensitive information about relay selection via a timing...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2012-3518

Low priority

Some fixes available 10 of 14

The networkstatus_parse_vote_from_string function in routerparse.c in Tor before 0.2.2.38 does not properly handle an invalid flavor name, which allows remote attackers to cause a denial of service (out-of-bounds read and daemon...

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2012-3517

Medium priority

Some fixes available 10 of 14

Use-after-free vulnerability in dns.c in Tor before 0.2.2.38 might allow remote attackers to cause a denial of service (daemon crash) via vectors related to failed DNS requests.

1 affected package

tor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor — — — — —
Show less packages

CVE-2012-4000

Medium priority

Some fixes available 3 of 5

Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerpages/server-scripts/spellchecker.php in FCKeditor 2.6.7 and earlier allows remote attackers to inject...

1 affected package

fckeditor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fckeditor — — — — —
Show less packages

CVE-2012-1147

Low priority
Ignored

readfilemap.c in expat before 2.1.0 allows context-dependent attackers to cause a denial of service (file descriptor consumption) via a large number of crafted XML files.

40 affected packages

apache2, apr-util, audacity, ayttm, cableswig...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
apache2 — — — — Ignored
apr-util — — — — Ignored
audacity — — — — Not affected
ayttm — — — — Not in release
cableswig — — — — Not in release
cadaver — — — — Not affected
celementtree — — — — Not in release
cmake — — — — Ignored
coin3 — — — — Not affected
expat — — — — Not affected
gdcm — — — — Not affected
ghostscript — — — — Ignored
grmonitor — — — — Not in release
insighttoolkit — — — — Not in release
kompozer — — — — Not in release
libparagui1.1 — — — — Not in release
matanza — — — — Not affected
paraview — — — — Not affected
poco — — — — Not affected
python-xml — — — — Not in release
python2.4 — — — — Not in release
python2.5 — — — — Not in release
python2.6 — — — — Not in release
simgear — — — — Not affected
sitecopy — — — — Not affected
smart — — — — Ignored
swish-e — — — — Not affected
tdom — — — — Not affected
texlive-bin — — — — Ignored
tla — — — — Not affected
vnc4 — — — — Ignored
vtk — — — — Not in release
w3c-libwww — — — — Not in release
wbxml2 — — — — Not affected
wxwidgets2.6 — — — — Not in release
wxwidgets2.8 — — — — Not in release
wxwindows2.4 — — — — Not in release
xmlrpc-c — — — — Ignored
xotcl — — — — Not affected
xulrunner — — — — Not in release
Show all 40 packages Show less packages