Vulnerabilities > Debian

DATE CVE VULNERABILITY TITLE RISK
2011-02-10 CVE-2011-0981 Improper Input Validation vulnerability in Google Chrome
Google Chrome before 9.0.597.94 does not properly perform event handling for animations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale pointer."
network
low complexity
google apple debian CWE-20
7.5
2011-02-04 CVE-2011-0783 Unspecified vulnerability in Google Chrome
Unspecified vulnerability in Google Chrome before 9.0.597.84 allows user-assisted remote attackers to cause a denial of service (application crash) via vectors involving a "bad volume setting."
network
google debian
4.3
2011-02-04 CVE-2011-0779 Improper Input Validation vulnerability in Google Chrome
Google Chrome before 9.0.597.84 does not properly handle a missing key in an extension, which allows remote attackers to cause a denial of service (application crash) via a crafted extension.
network
low complexity
google debian CWE-20
5.0
2011-01-28 CVE-2010-3689 Path Traversal vulnerability in multiple products
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
6.9
2011-01-28 CVE-2010-3454 Off-by-one Error vulnerability in multiple products
Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted typography information in a Microsoft Word .DOC file that triggers an out-of-bounds write.
network
apache canonical debian CWE-193
critical
9.3
2011-01-28 CVE-2010-3452 Use After Free vulnerability in multiple products
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.
network
apache canonical debian CWE-416
critical
9.3
2011-01-28 CVE-2010-3451 Use After Free vulnerability in multiple products
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via malformed tables in an RTF document.
network
apache canonical debian CWE-416
critical
9.3
2011-01-28 CVE-2010-3450 Path Traversal vulnerability in multiple products
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a ..
network
apache canonical debian CWE-22
critical
9.3
2011-01-20 CVE-2011-0495 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Digium Asterisk
Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.
6.0
2011-01-20 CVE-2010-4338 Link Following vulnerability in Jwilk Ocrodjvu 0.4.61
ocrodjvu 0.4.6-1 on Debian GNU/Linux allows local users to modify arbitrary files via a symlink attack on temporary files that are generated when Cuneiform is invoked as the OCR engine.
local
high complexity
jwilk debian CWE-59
6.2