Vulnerabilities > Debian > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-12 CVE-2019-18848 Improper Authentication vulnerability in multiple products
The json-jwt gem before 1.11.0 for Ruby lacks an element count during the splitting of a JWE string.
network
low complexity
json-jwt-project debian CWE-287
5.0
2019-11-12 CVE-2011-3618 Link Following vulnerability in multiple products
atop: symlink attack possible due to insecure tempfile handling
local
low complexity
atop-project debian CWE-59
4.6
2019-11-11 CVE-2019-18849 Out-of-bounds Read vulnerability in multiple products
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.
5.5
2019-11-08 CVE-2019-14824 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values.
network
low complexity
fedoraproject redhat debian CWE-732
6.5
2019-11-07 CVE-2013-1811 Improper Input Validation vulnerability in multiple products
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
network
low complexity
mantisbt debian CWE-20
4.0
2019-11-07 CVE-2013-1809 Link Following vulnerability in multiple products
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
network
low complexity
gambas-project debian CWE-59
6.4
2019-11-07 CVE-2013-1429 Link Following vulnerability in multiple products
Lintian before 2.5.12 allows remote attackers to gather information about the "host" system using crafted symlinks.
local
low complexity
debian canonical CWE-59
6.3
2019-11-07 CVE-2007-5743 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
4.3
2019-11-07 CVE-2013-1425 Incorrect Default Permissions vulnerability in multiple products
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
local
low complexity
ldap-git-backup-project debian CWE-276
5.5
2019-11-07 CVE-2010-2450 Use of Password Hash With Insufficient Computational Effort vulnerability in multiple products
The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm.
network
low complexity
shibboleth debian CWE-916
5.0