Vulnerabilities > Debian > Debian Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-13 CVE-2010-4653 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
network
low complexity
freedesktop debian CWE-190
6.5
2019-11-13 CVE-2010-4532 Improper Certificate Validation vulnerability in multiple products
offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.
network
high complexity
debian offlineimap CWE-295
5.9
2019-11-13 CVE-2012-4385 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
letodms 3.3.6 has CSRF via change password
network
low complexity
trilexnet debian CWE-352
6.5
2019-11-13 CVE-2012-4384 Cross-site Scripting vulnerability in multiple products
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
network
low complexity
trilexnet debian CWE-79
6.1
2019-11-12 CVE-2010-3440 Download of Code Without Integrity Check vulnerability in multiple products
babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.
local
low complexity
babiloo-project debian CWE-494
5.5
2019-11-12 CVE-2010-3299 Missing Encryption of Sensitive Data vulnerability in multiple products
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
network
low complexity
rubyonrails debian CWE-311
6.5
2019-11-12 CVE-2010-3439 Improper Input Validation vulnerability in multiple products
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.
network
low complexity
cor-entertainment debian fedoraproject CWE-20
6.5
2019-11-12 CVE-2010-3359 Improper Input Validation vulnerability in multiple products
If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory.
local
low complexity
gargoyle-project debian CWE-20
4.8
2019-11-11 CVE-2019-18849 Out-of-bounds Read vulnerability in multiple products
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.
5.5
2019-11-08 CVE-2019-14824 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values.
network
low complexity
fedoraproject redhat debian CWE-732
6.5