Vulnerabilities > Debian > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-07 CVE-2013-1425 Incorrect Default Permissions vulnerability in multiple products
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
local
low complexity
ldap-git-backup-project debian CWE-276
5.5
2019-11-07 CVE-2012-0049 Resource Exhaustion vulnerability in multiple products
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
network
low complexity
openttd debian fedoraproject CWE-400
4.3
2019-11-07 CVE-2019-18809 Memory Leak vulnerability in multiple products
A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.
4.6
2019-11-06 CVE-2009-5046 Cross-site Scripting vulnerability in multiple products
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
network
low complexity
eclipse debian CWE-79
6.1
2019-11-06 CVE-2009-5049 Cross-site Scripting vulnerability in multiple products
WebApp JSP Snoop page XSS in jetty though 6.1.21.
network
low complexity
mortbay debian CWE-79
6.1
2019-11-06 CVE-2010-2471 Open Redirect vulnerability in multiple products
Drupal versions 5.x and 6.x has open redirection
network
low complexity
drupal debian CWE-601
6.1
2019-11-06 CVE-2011-4900 Information Exposure vulnerability in multiple products
TYPO3 before 4.5.4 allows Information Disclosure in the backend.
network
low complexity
typo3 debian CWE-200
6.5
2019-11-05 CVE-2019-5068 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2.
local
low complexity
mesa3d opensuse debian canonical CWE-732
4.4
2019-11-05 CVE-2013-5123 Improper Authentication vulnerability in multiple products
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
network
high complexity
pypa virtualenv fedoraproject redhat debian CWE-287
5.9
2019-11-05 CVE-2010-3674 Cross-site Scripting vulnerability in multiple products
TYPO3 before 4.4.1 allows XSS in the frontend search box.
network
low complexity
typo3 debian CWE-79
6.1