VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Debian
> Medium
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2020-05-29
CVE-2020-11086
In FreeRDP less than or equal to 2.0.0, there is an out-of-bound read in ntlm_read_ntlm_v2_client_challenge that reads up to 28 bytes out-of-bound to an internal structure.
network
low complexity
freerdp
opensuse
debian
5.4
5.4
2020-05-29
CVE-2020-11039
In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and written due to integer overflows in length checks.
network
low complexity
freerdp
opensuse
debian
6.8
6.8
2020-05-29
CVE-2020-11038
In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists.
network
low complexity
freerdp
opensuse
debian
5.4
5.4
2020-05-29
CVE-2020-11019
In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an invalid array index.
network
low complexity
freerdp
opensuse
debian
6.5
6.5
2020-05-29
CVE-2020-11018
In FreeRDP less than or equal to 2.0.0, a possible resource exhaustion vulnerability can be performed.
network
low complexity
freerdp
opensuse
debian
6.5
6.5
2020-05-29
CVE-2020-11017
In FreeRDP less than or equal to 2.0.0, by providing manipulated input a malicious client can create a double free condition and crash the server.
network
low complexity
freerdp
opensuse
debian
6.5
6.5
2020-05-28
CVE-2020-11082
In Kaminari before 1.2.1, there is a vulnerability that would allow an attacker to inject arbitrary code into pages with pagination links.
network
low complexity
kaminari-project
debian
6.1
6.1
2020-05-28
CVE-2019-20807
OS Command Injection vulnerability in multiple products
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
local
low complexity
vim
debian
opensuse
canonical
apple
starwindsoftware
CWE-78
5.3
5.3
2020-05-27
CVE-2020-13632
NULL Pointer Dereference vulnerability in multiple products
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
local
low complexity
sqlite
fedoraproject
canonical
netapp
brocade
debian
siemens
oracle
CWE-476
5.5
5.5
2020-05-27
CVE-2020-13253
Out-of-bounds Read vulnerability in multiple products
sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations.
local
low complexity
qemu
canonical
debian
CWE-125
5.5
5.5
«
Previous
1
2
...
121
122
123
(current)
124
125
...
301
302
»
Next