Vulnerabilities > Debian > Debian Linux

DATE CVE VULNERABILITY TITLE RISK
2015-03-12 CVE-2015-2045 Information Exposure vulnerability in multiple products
The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors.
local
low complexity
xen fedoraproject debian CWE-200
2.1
2015-03-09 CVE-2015-1165 Information Exposure vulnerability in multiple products
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
network
low complexity
debian fedoraproject bestpractical CWE-200
5.0
2015-03-09 CVE-2014-9472 Resource Management Errors vulnerability in multiple products
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.
7.1
2015-02-28 CVE-2015-0885 Resource Management Errors vulnerability in multiple products
checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.
network
low complexity
debian checkpw-project CWE-399
5.0
2015-02-27 CVE-2015-1414 Remote Denial of Service vulnerability in FreeBSD
Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10.
network
low complexity
netgate debian freebsd
7.8
2015-02-24 CVE-2015-1572 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in closefs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code by causing a crafted block group descriptor to be marked as dirty.
local
low complexity
e2fsprogs-project debian canonical CWE-119
4.6
2015-02-23 CVE-2015-2047 Improper Authentication vulnerability in multiple products
The rsaauth extension in TYPO3 4.3.0 through 4.3.14, 4.4.0 through 4.4.15, 4.5.0 through 4.5.39, and 4.6.0 through 4.6.18, when configured for the frontend, allows remote attackers to bypass authentication via a password that is casted to an empty value.
network
high complexity
typo3 debian CWE-287
2.6
2015-02-19 CVE-2015-1592 Injection vulnerability in multiple products
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use the Perl Storable::thaw function, which allows remote attackers to include and execute arbitrary local Perl files and possibly execute arbitrary code via unspecified vectors.
network
low complexity
debian sixapart CWE-74
7.5
2015-02-17 CVE-2015-0247 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
4.6
2015-02-08 CVE-2014-9675 Permissions, Privileges, and Access Controls vulnerability in multiple products
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
5.0