Vulnerabilities > Debian > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-10-31 CVE-2019-18424 OS Command Injection vulnerability in multiple products
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device.
6.8
2019-10-31 CVE-2019-18420 Use of Externally-Controlled Format String vulnerability in multiple products
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via a VCPUOP_initialise hypercall.
network
low complexity
xen debian fedoraproject CWE-134
6.5
2019-10-30 CVE-2010-0749 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.
network
low complexity
transmissionbt linux debian CWE-119
5.0
2019-10-30 CVE-2010-0747 Incorrect Permission Assignment for Critical Resource vulnerability in Linbit Drbd8 2.6.26
drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.
local
low complexity
linbit debian CWE-732
4.6
2019-10-30 CVE-2010-0207 Infinite Loop vulnerability in Xpdfreader Xpdf 3.0317/3.0413/3.044
In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
4.3
2019-10-30 CVE-2010-0206 NULL Pointer Dereference vulnerability in Xpdfreader Xpdf 3.0317/3.0413/3.044
xpdf allows remote attackers to cause a denial of service (NULL pointer dereference and crash) in the way it processes JBIG2 PDF stream objects.
4.3
2019-10-30 CVE-2018-5735 Reachable Assertion vulnerability in Debian Linux 10.0/8.0/9.0
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected.
network
low complexity
debian CWE-617
5.0
2019-10-29 CVE-2011-1408 Link Following vulnerability in multiple products
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
network
low complexity
ikiwiki debian CWE-59
6.4
2019-10-29 CVE-2019-18603 Use of Uninitialized Resource vulnerability in multiple products
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer.
4.3
2019-10-29 CVE-2019-18602 Use of Uninitialized Resource vulnerability in multiple products
OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.
network
low complexity
openafs debian CWE-908
5.0