This page lists packages that are affected by issues that are considered unimportant from a security perspective. These issues are thought to be unexploitable or uneffective in most situations (for example, browser denial-of-services).
| Package | Bug | Description | Releases |
|---|---|---|---|
| aolserver4 | CVE-2009-4494 | AOLserver 4.5.1 writes data to a log file without sanitizing ... | sid, squeeze, wheezy |
| apache2 | CVE-2001-1534 | mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's ... | sid, squeeze, wheezy |
| CVE-2003-1307 | ** DISPUTED ** ... | sid, squeeze, wheezy | |
| CVE-2003-1580 | The Apache HTTP Server 2.0.44, when DNS resolution is enabled for ... | sid, squeeze, wheezy | |
| CVE-2003-1581 | The Apache HTTP Server 2.0.44, when DNS resolution is enabled for ... | sid, squeeze, wheezy | |
| CVE-2007-0086 | ** DISPUTED ** ... | sid, squeeze, wheezy | |
| CVE-2007-1743 | suexec in Apache HTTP Server (httpd) 2.2.3 does not verify ... | sid, squeeze, wheezy | |
| CVE-2007-3303 | Apache httpd 2.0.59 and 2.2.4, with the Prefork MPM module, allows ... | sid, squeeze, wheezy | |
| CVE-2008-0455 | Cross-site scripting (XSS) vulnerability in the mod_negotiation module ... | sid, squeeze, wheezy | |
| CVE-2008-0456 | CRLF injection vulnerability in the mod_negotiation module in the ... | sid, squeeze, wheezy | |
| CVE-2011-4415 | The ap_pregsub function in server/util.c in the Apache HTTP Server ... | sid, squeeze, wheezy | |
| apt | CVE-2011-3374 | apt-key insecure validation | sid, squeeze, wheezy |
| apt-setup | CVE-2005-2214 | apt-setup in Debian GNU/Linux installs the apt.conf file with insecure ... | sid, squeeze, wheezy |
| arora | CVE-2011-3367 | Arora, possibly 0.11 and other versions, does not use a certain font ... | sid, squeeze, wheezy |
| awffull | CVE-2007-0510 | Multiple buffer overflows in (1) graphs.c, (2) output.c, and (3) ... | sid, squeeze, wheezy |
| axis | CVE-2007-2353 | Apache Axis 1.0 allows remote attackers to obtain sensitive ... | sid, squeeze, wheezy |
| bacula | CVE-2007-5626 | make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a ... | sid, squeeze, wheezy |
| banshee | CVE-2009-1175 | Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in ... | sid, squeeze, wheezy |
| blender | CVE-2005-3151 | Buffer overflow in blenderplay in Blender Player 2.37a allows ... | sid, squeeze, wheezy |
| CVE-2009-3850 | Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to ... | sid, squeeze, wheezy | |
| boa | CVE-2009-4496 | Boa 0.94.14rc21 writes data to a log file without sanitizing ... | sid, squeeze, wheezy |
| bochs | CVE-2007-2894 | The emulated floppy disk controller in Bochs 2.3 allows local users of ... | sid, squeeze, wheezy |
| bugzilla | CVE-2006-2420 | Bugzilla 2.20rc1 through 2.20 and 2.21.1, when using RSS 1.0, allows ... | squeeze |
| CVE-2008-6098 | Bugzilla 3.2 before 3.2 RC2, 3.0 before 3.0.6, 2.22 before 2.22.6, ... | squeeze | |
| busybox | CVE-2011-2716 | sid, squeeze, wheezy | |
| cableswig | CVE-2009-3560 | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, ... | sid, squeeze, wheezy |
| CVE-2009-3720 | The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ... | sid, squeeze, wheezy | |
| cacti | CVE-2009-4112 | Cacti 0.8.7e and earlier allows remote authenticated administrators to ... | sid, squeeze, wheezy |
| cadaver | CVE-2009-3560 | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, ... | sid, squeeze, wheezy |
| CVE-2009-3720 | The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ... | sid, squeeze, wheezy | |
| chromium-browser | CVE-2008-5749 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| CVE-2008-7246 | Google Chrome 0.2.149.29 and earlier allows remote attackers to cause ... | sid, squeeze, wheezy | |
| CVE-2009-0374 | ** DISPUTED ** ... | sid, squeeze, wheezy | |
| CVE-2009-1598 | Google Chrome executes DOM calls in response to a javascript: URI in ... | sid, squeeze, wheezy | |
| CVE-2009-3011 | Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and ... | sid, squeeze, wheezy | |
| CVE-2010-1384 | Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and ... | sid, squeeze, wheezy | |
| CVE-2010-1992 | Google Chrome 1.0.154.48 executes a mail application in situations ... | sid, squeeze, wheezy | |
| CVE-2010-2120 | Google Chrome 1.0.154.48 allows remote attackers to cause a denial of ... | sid, squeeze, wheezy | |
| CVE-2010-4037 | Unspecified vulnerability in Google Chrome before 7.0.517.41 allows ... | sid, squeeze, wheezy | |
| CVE-2010-4482 | Unspecified vulnerability in Google Chrome before 8.0.552.215 allows ... | sid, squeeze, wheezy | |
| CVE-2010-4484 | Google Chrome before 8.0.552.215 does not properly handle HTML5 ... | sid, wheezy | |
| CVE-2010-4485 | Google Chrome before 8.0.552.215 does not properly restrict the ... | sid, squeeze, wheezy | |
| CVE-2010-4488 | Google Chrome before 8.0.552.215 does not properly handle HTTP proxy ... | sid, wheezy | |
| CVE-2011-0781 | Google Chrome before 9.0.597.84 does not properly handle autofill ... | squeeze | |
| CVE-2011-1194 | Multiple unspecified vulnerabilities in Google Chrome before ... | sid, squeeze, wheezy | |
| CVE-2011-1304 | Unspecified vulnerability in Google Chrome before 11.0.696.57 allows ... | squeeze | |
| CVE-2011-1450 | Google Chrome before 11.0.696.57 does not properly present file ... | squeeze | |
| CVE-2011-1801 | Unspecified vulnerability in Google Chrome before 11.0.696.71 allows ... | squeeze | |
| CVE-2011-1812 | Google Chrome before 12.0.742.91 allows remote attackers to bypass ... | squeeze | |
| CVE-2011-1815 | Google Chrome before 12.0.742.91 allows remote attackers to inject ... | squeeze | |
| CVE-2011-1819 | Google Chrome before 12.0.742.91 allows remote attackers to perform ... | squeeze | |
| CVE-2011-2358 | Google Chrome before 13.0.782.107 does not ensure that extension ... | squeeze | |
| CVE-2011-2360 | Google Chrome before 13.0.782.107 does not ensure that the user is ... | squeeze | |
| CVE-2011-2361 | The Basic Authentication dialog implementation in Google Chrome before ... | squeeze | |
| CVE-2011-2791 | The International Components for Unicode (ICU) functionality in Google ... | squeeze | |
| CVE-2011-2836 | Google Chrome before 14.0.835.163 does not require Infobar interaction ... | squeeze | |
| CVE-2011-3420 | Multiple unspecified vulnerabilities in Google Chrome before ... | squeeze | |
| CVE-2011-3421 | Multiple unspecified vulnerabilities in Google Chrome before ... | squeeze | |
| CVE-2011-3875 | Google Chrome before 15.0.874.102 does not properly handle drag and ... | squeeze | |
| CVE-2011-3879 | Google Chrome before 15.0.874.102 does not prevent redirects to ... | squeeze | |
| CVE-2011-3880 | Google Chrome before 15.0.874.102 does not prevent use of an ... | squeeze | |
| CVE-2011-3898 | Google Chrome before 15.0.874.120, when Java Runtime Environment (JRE) ... | squeeze | |
| CVE-2011-4691 | Google Chrome 15.0.874.121 and earlier does not prevent capture of ... | sid, squeeze, wheezy | |
| CVE-2011-4692 | WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 ... | sid, squeeze, wheezy | |
| clamav | CVE-2005-3229 | Multiple interpretation error in unspecified versions of ClamAV ... | sid, squeeze, wheezy |
| CVE-2007-6596 | ClamAV 0.92 does not recognize Base64 UUEncoded archives, which allows ... | sid, squeeze, wheezy | |
| coin3 | CVE-2009-3560 | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, ... | sid, squeeze, wheezy |
| CVE-2009-3720 | The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ... | sid, squeeze, wheezy | |
| courier | CVE-2004-2313 | Inter7 SqWebMail 3.4.1 through 3.6.1 generates different error ... | sid, squeeze, wheezy |
| CVE-2005-1308 | SqWebMail allows remote attackers to inject arbitrary web script or ... | sid, squeeze, wheezy | |
| ctn | CVE-2008-5146 | add-accession-numbers in ctn 3.0.6 allows local users to overwrite ... | sid, squeeze, wheezy |
| dbus | CVE-2011-2533 | The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows ... | squeeze |
| dietlibc | CVE-2012-1577 | squeeze | |
| dillo | TEMP-0560108-565B70 | browser-based css info disclosure | sid, wheezy |
| dirmngr | CVE-2011-2207 | sid, squeeze, wheezy | |
| dnspython | CVE-2008-1447 | The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, ... | sid, squeeze, wheezy |
| dovecot | CVE-2008-4870 | dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly ... | sid, squeeze, wheezy |
| CVE-2011-4318 | sid, squeeze, wheezy | ||
| dpkg-cross | CVE-2008-4950 | ** DISPUTED ** gccross in dpkg-cross 2.3.0 allows local users to ... | sid, squeeze, wheezy |
| dropbear | CVE-2006-1206 | Matt Johnston Dropbear SSH server 0.47 and earlier, as used in ... | sid, squeeze, wheezy |
| drupal6 | TEMP-0000000-57BF72 | XSS in drupal printing module | sid, squeeze, wheezy |
| TEMP-0000000-8FB0B7 | XSS in drupal 6 calendar field | sid, squeeze, wheezy | |
| drupal7 | CVE-2007-6752 | ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability in ... | sid, wheezy |
| eglibc | CVE-2010-3192 | Certain run-time memory protection mechanisms in the GNU C Library ... | sid, squeeze, wheezy |
| CVE-2010-4051 | The regcomp implementation in the GNU C Library (aka glibc or libc6) ... | sid, squeeze, wheezy | |
| CVE-2010-4052 | Stack consumption vulnerability in the regcomp implementation in the ... | sid, squeeze, wheezy | |
| CVE-2010-4756 | The glob implementation in the GNU C Library (aka glibc or libc6) ... | sid, squeeze, wheezy | |
| enigmail | CVE-2007-1264 | Enigmail 0.94.2 and earlier does not properly use the --status-fd ... | sid, squeeze, wheezy |
| epiphany-browser | CVE-2007-1084 | Mozilla Firefox 2.0.0.1 and earlier does not prompt users before ... | sid, squeeze, wheezy |
| TEMP-0560108-565B70 | browser-based css info disclosure | sid, squeeze, wheezy | |
| erlang | CVE-2009-0130 | ** DISPUTED ** lib/crypto/c_src/crypto_drv.c in erlang does not ... | sid, squeeze, wheezy |
| ettercap | CVE-2010-3843 | sid, squeeze, wheezy | |
| CVE-2010-3844 | sid, squeeze, wheezy | ||
| evolution | CVE-2007-1266 | Evolution 2.8.1 and earlier does not properly use the --status-fd ... | sid, squeeze, wheezy |
| CVE-2011-3201 | sid, squeeze, wheezy | ||
| fcron | CVE-2010-0792 | fcrontab in fcron before 3.0.5 allows local users to read arbitrary ... | squeeze |
| fetchmail | CVE-2011-1947 | fetchmail 5.9.9 through 6.3.19 does not properly limit the wait time ... | sid, squeeze, wheezy |
| ffmpeg | CVE-2008-4610 | MPlayer allows remote attackers to cause a denial of service ... | squeeze |
| CVE-2009-4639 | The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows ... | squeeze | |
| firehol | CVE-2008-4953 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| foomatic-filters | CVE-2011-2923 | sid, squeeze, wheezy | |
| freebsd-sendpr | CVE-2008-5142 | sendbug in freebsd-sendpr 3.113+5.3 on Debian GNU/Linux allows local ... | sid, squeeze, wheezy |
| freeradius | CVE-2007-0080 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| freetype | CVE-2012-1126 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze |
| CVE-2012-1127 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1128 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1129 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1130 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1131 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1132 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1135 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1137 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1138 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1139 | Array index error in FreeType before 2.4.9, as used in Mozilla Firefox ... | squeeze | |
| CVE-2012-1140 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1141 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| CVE-2012-1143 | FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 ... | squeeze | |
| freevo | CVE-2008-4955 | freevo.real in freevo 1.8.1 allows local users to overwrite arbitrary ... | sid, squeeze, wheezy |
| galeon | CVE-2007-3145 | Visual truncation vulnerability in Galeon 2.0.1 allows remote ... | squeeze |
| TEMP-0560108-565B70 | browser-based css info disclosure | squeeze | |
| gallery | CVE-2008-3600 | Directory traversal vulnerability in contrib/phpBB2/modules.php in ... | sid, squeeze, wheezy |
| gallery2 | CVE-2006-4976 | The Date Library in John Lim ADOdb Library for PHP allows remote ... | sid |
| gdb | CVE-2006-4146 | Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 ... | sid, squeeze, wheezy |
| CVE-2011-4355 | gdb: arbitrary code execution via .debug_gdb_scripts | sid, squeeze, wheezy | |
| ghostscript | TEMP-0000000-2EA6C5 | NULL dereferences, similar to Adobe's CVE-2009-0658 | sid, squeeze, wheezy |
| gimp | CVE-2007-3126 | Gimp 2.3.14 allows context-dependent attackers to cause a denial of ... | sid, squeeze, wheezy |
| glib2.0 | CVE-2012-0039 | ** DISPUTED ** GLib 2.31.8 and earlier, when the g_str_hash function ... | sid, squeeze, wheezy |
| glpi | CVE-2010-1618 | Cross-site scripting (XSS) vulnerability in the phpCAS client library ... | sid, squeeze, wheezy |
| CVE-2010-2795 | phpCAS before 1.1.2 allows remote authenticated users to hijack ... | sid, squeeze, wheezy | |
| CVE-2010-2796 | Cross-site scripting (XSS) vulnerability in phpCAS before 1.1.2, when ... | sid, squeeze, wheezy | |
| CVE-2010-3690 | Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before ... | sid, squeeze, wheezy | |
| CVE-2010-3691 | PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is ... | sid, squeeze, wheezy | |
| CVE-2010-3692 | Directory traversal vulnerability in the callback function in ... | sid, squeeze, wheezy | |
| CVE-2011-2720 | The autocompletion functionality in GLPI before 0.80.2 does not ... | squeeze | |
| CVE-2012-1104 | squeeze | ||
| CVE-2012-1105 | squeeze | ||
| gnumail | CVE-2007-1269 | GNUMail 1.1.2 and earlier does not properly use the --status-fd ... | sid, squeeze, wheezy |
| gpw | CVE-2011-4931 | sid, squeeze, wheezy | |
| grub | CVE-2008-3896 | Grub Legacy 0.97 and earlier stores pre-boot authentication passwords ... | sid, squeeze, wheezy |
| gwt | CVE-2007-2378 | The Google Web Toolkit (GWT) framework exchanges data using JavaScript ... | sid, squeeze |
| hex-a-hop | TEMP-0528250-2E3658 | hex-a-hop: buffer overflow in loading save games | sid, squeeze, wheezy |
| horde3 | CVE-2010-1638 | The IMP plugin in Horde allows remote attackers to bypass firewall ... | sid, squeeze, wheezy |
| iceape | CVE-2006-0496 | Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and ... | sid, squeeze, wheezy |
| CVE-2007-1084 | Mozilla Firefox 2.0.0.1 and earlier does not prompt users before ... | sid, squeeze, wheezy | |
| CVE-2007-4357 | Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof ... | sid, squeeze, wheezy | |
| CVE-2009-3560 | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, ... | sid, squeeze, wheezy | |
| CVE-2009-3720 | The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ... | sid, squeeze, wheezy | |
| CVE-2009-4629 | Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other ... | sid, squeeze, wheezy | |
| CVE-2010-1986 | Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to ... | sid, squeeze, wheezy | |
| CVE-2010-1987 | Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to ... | sid, squeeze, wheezy | |
| CVE-2010-1988 | Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to ... | sid, squeeze, wheezy | |
| CVE-2010-1990 | Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, ... | sid, squeeze, wheezy | |
| icecast2 | CVE-2005-0837 | IceCast 2.20 allows remote attackers to bypass the XSL parser and ... | sid, squeeze, wheezy |
| CVE-2005-0838 | Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow ... | sid, squeeze, wheezy | |
| icedove | CVE-2006-5633 | Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers ... | sid, squeeze, wheezy |
| CVE-2008-5430 | Mozilla Thunderbird 2.0.14 does not properly handle (1) ... | sid, squeeze, wheezy | |
| iceweasel | CVE-2002-2436 | The Cascading Style Sheets (CSS) implementation in Mozilla Firefox ... | squeeze |
| CVE-2002-2437 | The JavaScript implementation in Mozilla Firefox before 4.0, ... | squeeze | |
| CVE-2004-1639 | Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows ... | sid, squeeze, wheezy | |
| CVE-2005-2395 | Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the ... | sid, squeeze, wheezy | |
| CVE-2005-4685 | Firefox and Mozilla can associate a cookie with multiple domains when ... | sid, squeeze, wheezy | |
| CVE-2006-2723 | Unspecified versions of Mozilla Firefox allow remote attackers to ... | sid, squeeze, wheezy | |
| CVE-2006-5633 | Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers ... | sid, squeeze, wheezy | |
| CVE-2006-6954 | Flock beta 1 0.7 allows remote attackers to cause a denial of service ... | sid, squeeze, wheezy | |
| CVE-2007-1084 | Mozilla Firefox 2.0.0.1 and earlier does not prompt users before ... | sid, squeeze, wheezy | |
| CVE-2007-1256 | Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address ... | sid, squeeze, wheezy | |
| CVE-2007-1736 | Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or ... | sid, squeeze, wheezy | |
| CVE-2007-1970 | Mozilla Firefox does not warn the user about HTTP elements on an HTTPS ... | sid, squeeze, wheezy | |
| CVE-2007-2162 | (1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote ... | sid, squeeze, wheezy | |
| CVE-2007-2671 | Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of ... | sid, squeeze, wheezy | |
| CVE-2007-4357 | Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof ... | sid, squeeze, wheezy | |
| CVE-2007-5415 | Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when ... | sid, squeeze, wheezy | |
| CVE-2007-5896 | Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of ... | sid, squeeze, wheezy | |
| CVE-2007-6715 | Mozilla Firefox allows remote attackers to cause a denial of service ... | sid, squeeze, wheezy | |
| CVE-2008-2014 | Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial ... | sid, squeeze, wheezy | |
| CVE-2008-3444 | The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows ... | sid, squeeze, wheezy | |
| CVE-2008-4324 | The user interface event dispatcher in Mozilla Firefox 3.0.3 on ... | sid, squeeze, wheezy | |
| CVE-2008-5715 | Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to ... | sid, squeeze, wheezy | |
| CVE-2008-7293 | Mozilla Firefox before 4 cannot properly restrict modifications to ... | squeeze | |
| CVE-2009-0071 | Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is ... | sid, squeeze, wheezy | |
| CVE-2009-0821 | Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause ... | sid, squeeze, wheezy | |
| CVE-2009-3010 | Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; ... | sid, squeeze, wheezy | |
| CVE-2009-3014 | Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; ... | sid, squeeze, wheezy | |
| CVE-2010-5074 | The layout engine in Mozilla Firefox before 4.0, Thunderbird before ... | squeeze | |
| CVE-2011-0082 | The X.509 certificate validation functionality in Mozilla Firefox ... | sid, squeeze, wheezy | |
| CVE-2011-1712 | The txXPathNodeUtils::getXSLTId function in ... | squeeze | |
| CVE-2011-4688 | Mozilla Firefox 8.0.1 and earlier does not prevent capture of data ... | sid, squeeze, wheezy | |
| imagemagick | CVE-2005-0406 | A design flaw in image processing software that modifies JPEG images ... | sid, squeeze, wheezy |
| CVE-2008-3134 | Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 ... | sid, squeeze, wheezy | |
| initramfs-tools | CVE-2008-4996 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| iproute | CVE-2012-1088 | squeeze | |
| irssi-plugin-otr | TEMP-0569506-737DDE | irssi emote leak | sid, squeeze, wheezy |
| jetty | CVE-2009-3579 | Cross-site scripting (XSS) vulnerability in the CookieDump.java sample ... | sid, squeeze, wheezy |
| kazehakase | TEMP-0560108-565B70 | browser-based css info disclosure | squeeze |
| kde4libs | CVE-2009-1692 | WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, ... | sid, squeeze, wheezy |
| CVE-2009-1718 | WebKit in Apple Safari before 4.0 allows user-assisted remote ... | sid, squeeze, wheezy | |
| CVE-2009-1724 | Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari ... | sid, squeeze, wheezy | |
| CVE-2009-3015 | QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and ... | sid, squeeze, wheezy | |
| CVE-2009-3272 | Stack consumption vulnerability in WebKit.dll in WebKit in Apple ... | sid, squeeze, wheezy | |
| TEMP-0560108-565B70 | browser-based css info disclosure | sid, squeeze, wheezy | |
| TEMP-0568486-B6FCB6 | browser javascript document.write denial-of-service | sid, squeeze, wheezy | |
| kdebase | CVE-2005-4684 | Konqueror can associate a cookie with multiple domains when the DNS ... | squeeze |
| CVE-2006-6015 | Buffer overflow in the JavaScript implementation in Safari on Apple ... | squeeze | |
| CVE-2007-4229 | Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows ... | squeeze | |
| CVE-2007-5963 | Unspecified vulnerability in kdebase allows local users to cause a ... | squeeze | |
| CVE-2007-6000 | KDE Konqueror 3.5.6 and earlier allows remote attackers to cause a ... | squeeze | |
| CVE-2008-4382 | Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of ... | squeeze | |
| CVE-2008-4514 | The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to ... | squeeze | |
| CVE-2008-5698 | HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 ... | squeeze | |
| CVE-2008-5712 | The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to ... | squeeze | |
| CVE-2009-2537 | KDE Konqueror allows remote attackers to cause a denial of service ... | squeeze | |
| TEMP-0325369-6C1D5E | kdebase uses urandom as an entropy source | squeeze | |
| TEMP-0515106-13A33A | konqueror: potential exploits via application launchers | squeeze | |
| TEMP-0532514-9137E0 | predictable random number generator used in web browsers | squeeze | |
| kdebase-workspace | CVE-2011-5054 | kcheckpass passes a user-supplied argument to the pam_start function, ... | squeeze |
| kdegraphics | CVE-2006-6297 | Stack consumption vulnerability in the KFILE JPEG (kfile_jpeg) plugin ... | squeeze |
| kdelibs | CVE-2007-1308 | ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE ... | squeeze |
| CVE-2007-1565 | Konqueror 3.5.5 allows remote attackers to cause a denial of service ... | squeeze | |
| CVE-2007-2164 | Konqueror 3.5.5 release 45.4 allows remote attackers to cause a denial ... | squeeze | |
| CVE-2009-1692 | WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, ... | squeeze | |
| CVE-2009-1718 | WebKit in Apple Safari before 4.0 allows user-assisted remote ... | squeeze | |
| CVE-2009-1724 | Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari ... | squeeze | |
| CVE-2009-3015 | QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and ... | squeeze | |
| CVE-2009-3272 | Stack consumption vulnerability in WebKit.dll in WebKit in Apple ... | squeeze | |
| TEMP-0560108-565B70 | browser-based css info disclosure | squeeze | |
| TEMP-0568486-B6FCB6 | browser javascript document.write denial-of-service | squeeze | |
| kdepim | CVE-2006-7139 | Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, ... | sid, squeeze, wheezy |
| CVE-2007-1265 | KMail 1.9.5 and earlier does not properly use the --status-fd argument ... | sid, squeeze, wheezy | |
| koffice | CVE-2007-0104 | The Adobe PDF specification 1.3, as implemented by (a) xpdf 3.0.1 ... | sid, squeeze, wheezy |
| kompozer | CVE-2009-1305 | The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird ... | sid, squeeze |
| CVE-2009-1309 | Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not ... | sid, squeeze | |
| CVE-2009-1312 | Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block ... | sid, squeeze | |
| CVE-2009-3371 | Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 ... | sid, squeeze | |
| krb5 | CVE-2004-0971 | The krb5-send-pr script in the kerberos5 (krb5) package in Trustix ... | sid, squeeze, wheezy |
| lbreakout2 | TEMP-0608980-E8B8DF | Crash with long HOME environment variable | sid, squeeze, wheezy |
| lftp | CVE-2007-2348 | mirror --script in lftp before 3.5.9 does not properly quote shell ... | sid, squeeze, wheezy |
| libgd2 | CVE-2007-3472 | Integer overflow in gdImageCreateTrueColor function in the GD Graphics ... | sid, squeeze, wheezy |
| CVE-2007-3473 | The gdImageCreateXbm function in the GD Graphics Library (libgd) ... | sid, squeeze, wheezy | |
| CVE-2007-3475 | The GD Graphics Library (libgd) before 2.0.35 allows user-assisted ... | sid, squeeze, wheezy | |
| CVE-2007-3478 | Race condition in gdImageStringFTEx (gdft_draw_bitmap) in gdft.c in ... | sid, squeeze, wheezy | |
| libgnumail-java | CVE-2005-1105 | Directory traversal vulnerability in the MimeBodyPart.getFileName ... | sid, squeeze, wheezy |
| libpam-opie | CVE-2001-1483 | One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows ... | squeeze |
| libphp-adodb | CVE-2006-4976 | The Date Library in John Lim ADOdb Library for PHP allows remote ... | sid, squeeze, wheezy |
| CVE-2011-3699 | John Lim ADOdb Library for PHP 5.11 allows remote attackers to obtain ... | sid, squeeze, wheezy | |
| libsndfile | CVE-2009-4835 | The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, ... | sid, squeeze, wheezy |
| libstruts1.2-java | CVE-2012-1007 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts ... | sid, squeeze, wheezy |
| libwmf | CVE-2007-3476 | Array index error in gd_gif_in.c in the GD Graphics Library (libgd) ... | sid, squeeze, wheezy |
| CVE-2007-3477 | The (a) imagearc and (b) imagefilledarc functions in GD Graphics ... | sid, squeeze, wheezy | |
| CVE-2007-3996 | Multiple integer overflows in libgd in PHP before 5.2.4 allow remote ... | sid, squeeze, wheezy | |
| CVE-2009-3546 | The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before ... | sid, squeeze, wheezy | |
| TEMP-0601525-BEBB65 | libgd2: gdImageColorTransparent can write outside buffer | sid, squeeze, wheezy | |
| lilo | CVE-2008-3895 | LILO 22.6.1 and earlier stores pre-boot authentication passwords in ... | sid, squeeze, wheezy |
| linux-2.6 | CVE-2004-0230 | TCP, when using a large Window Size, makes it easier for remote ... | sid, squeeze, wheezy |
| CVE-2005-3660 | Linux kernel 2.4 and 2.6 allows attackers to cause a denial of service ... | sid, squeeze, wheezy | |
| CVE-2006-5701 | Double free vulnerability in squashfs module in the Linux kernel ... | sid, squeeze, wheezy | |
| CVE-2006-6128 | The ReiserFS functionality in Linux kernel 2.6.18, and possibly other ... | sid, squeeze, wheezy | |
| CVE-2007-3719 | The process scheduler in the Linux kernel 2.6.16 gives preference to ... | sid, squeeze, wheezy | |
| CVE-2008-4609 | The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, ... | sid, squeeze, wheezy | |
| CVE-2009-3888 | The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before ... | sid, squeeze, wheezy | |
| CVE-2010-4563 | The Linux kernel, when using IPv6, allows remote attackers to ... | sid, squeeze, wheezy | |
| CVE-2011-1019 | squeeze | ||
| CVE-2011-1585 | sid, wheezy | ||
| CVE-2011-4112 | squeeze | ||
| CVE-2011-4915 | sid, squeeze, wheezy | ||
| CVE-2011-4917 | sid, squeeze, wheezy | ||
| m2crypto | CVE-2009-0127 | ** DISPUTED ** M2Crypto does not properly check the return value from ... | sid, squeeze, wheezy |
| m4 | CVE-2008-1687 | The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before ... | sid, squeeze, wheezy |
| CVE-2008-1688 | Unspecified vulnerability in GNU m4 before 1.4.11 might allow ... | sid, squeeze, wheezy | |
| magpierss | CVE-2006-4735 | Kellan Elliott-McCrea MagpieRSS allows remote attackers to obtain ... | sid, squeeze, wheezy |
| maildirsync | CVE-2008-5150 | sample.sh in maildirsync 1.1 allows local users to append data to ... | sid, squeeze, wheezy |
| mailman | CVE-2006-2191 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| mailscanner | CVE-2010-3293 | mailscanner virus updates DoS | squeeze |
| matanza | CVE-2009-3560 | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, ... | sid, squeeze, wheezy |
| CVE-2009-3720 | The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ... | sid, squeeze, wheezy | |
| mediawiki | CVE-2007-0894 | MediaWiki before 1.9.2 allows remote attackers to obtain sensitive ... | sid, squeeze, wheezy |
| CVE-2008-5688 | MediaWiki 1.8.1, and other versions before 1.13.3, when the ... | sid, squeeze, wheezy | |
| mh-book | CVE-2008-5152 | inmail-show in mh-book 200605 allows local users to overwrite ... | sid, squeeze, wheezy |
| midori | CVE-2010-3900 | Midori before 0.2.5, when WebKitGTK+ before 1.1.14 or LibSoup before ... | squeeze |
| mini-httpd | CVE-2009-4490 | mini_httpd 1.19 writes data to a log file without sanitizing ... | sid, squeeze, wheezy |
| moin | CVE-2007-0902 | Unspecified vulnerability in the "Show debugging information" feature ... | sid, squeeze, wheezy |
| moodle | CVE-2006-4976 | The Date Library in John Lim ADOdb Library for PHP allows remote ... | sid, squeeze, wheezy |
| CVE-2008-0123 | Cross-site scripting (XSS) vulnerability in install.php for Moodle ... | sid, squeeze, wheezy | |
| CVE-2008-3327 | Moodle 1.6.5, when display_errors is enabled, allows remote attackers ... | sid, squeeze, wheezy | |
| mutt | CVE-2007-1268 | Mutt 1.5.13 and earlier does not properly use the --status-fd argument ... | sid, squeeze, wheezy |
| nagios3 | CVE-2008-5027 | The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor ... | sid, squeeze, wheezy |
| net-tools | CVE-2002-1976 | ifconfig, when used on the Linux kernel 2.2 and later, does not report ... | sid, squeeze, wheezy |
| nginx | CVE-2009-4487 | nginx 0.7.64 writes data to a log file without sanitizing ... | sid, squeeze, wheezy |
| ntop | TEMP-0335996-97467D | ntop format string vulnerability | sid, wheezy |
| nvidia-cg-toolkit | CVE-2008-5144 | nvidia-cg-toolkit-installer in nvidia-cg-toolkit 2.0.0015 allows local ... | sid, squeeze, wheezy |
| ocsinventory-server | CVE-2010-1733 | Multiple SQL injection vulnerabilities in OCS Inventory NG before ... | sid, squeeze, wheezy |
| CVE-2011-4024 | Cross-site scripting (XSS) vulnerability in ocsinventory in OCS ... | squeeze | |
| openconnect | CVE-2010-3902 | OpenConnect before 2.26 places the webvpn cookie value in the ... | squeeze |
| openjdk-6 | CVE-2007-0012 | Sun JRE 5.0 before update 14 allows remote attackers to cause a denial ... | sid, squeeze, wheezy |
| CVE-2007-5019 | Buffer overflow in the Sun Java Web Start ActiveX control in Java ... | sid, squeeze, wheezy | |
| openldap | CVE-2011-4079 | Off-by-one error in the UTF8StringNormalize function in OpenLDAP ... | squeeze |
| openoffice.org | CVE-2005-4636 | OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, ... | sid, squeeze, wheezy |
| CVE-2007-4251 | OpenOffice.org (OOo) 2.2 does not properly handle files with multiple ... | sid, squeeze, wheezy | |
| openssh | CVE-2007-2243 | OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is ... | sid, squeeze, wheezy |
| CVE-2007-2768 | OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, ... | sid, squeeze, wheezy | |
| CVE-2008-3234 | sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH ... | sid, squeeze, wheezy | |
| openssl | CVE-2010-0742 | The Cryptographic Message Syntax (CMS) implementation in ... | squeeze |
| CVE-2010-0928 | OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx ... | sid, squeeze, wheezy | |
| CVE-2011-4577 | OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is ... | squeeze | |
| openvpn | CVE-2006-2229 | OpenVPN 2.0.7 and earlier, when configured to use the --management ... | sid, squeeze, wheezy |
| os-prober | CVE-2008-5135 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| osc | CVE-2012-1095 | sid, squeeze, wheezy | |
| otrs2 | CVE-2010-4758 | installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an ... | squeeze |
| CVE-2010-4759 | Open Ticket Request System (OTRS) before 3.0.0-beta7 does not properly ... | squeeze | |
| CVE-2010-4760 | Open Ticket Request System (OTRS) before 3.0.0-beta6 adds ... | squeeze | |
| CVE-2010-4761 | The customer-interface ticket-print dialog in Open Ticket Request ... | squeeze | |
| CVE-2010-4762 | Cross-site scripting (XSS) vulnerability in the rich-text-editor ... | squeeze | |
| CVE-2010-4763 | The ACL-customer-status Ticket Type setting in Open Ticket Request ... | squeeze | |
| CVE-2010-4764 | Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, ... | squeeze | |
| pam | CVE-2010-3316 | The run_coprocess function in pam_xauth.c in the pam_xauth module in ... | squeeze |
| patch | CVE-2010-4651 | Directory traversal vulnerability in util.c in GNU patch 2.6.1 and ... | sid, squeeze, wheezy |
| paxtest | CVE-2010-3373 | squeeze | |
| perl | CVE-2010-4777 | sid, squeeze, wheezy | |
| CVE-2011-0761 | Perl 5.10.x allows context-dependent attackers to cause a denial of ... | squeeze | |
| CVE-2011-2728 | sid, squeeze, wheezy | ||
| CVE-2011-4116 | sid, squeeze, wheezy | ||
| php-apc | CVE-2010-3294 | Cross-site scripting (XSS) vulnerability in apc.php in the Alternative ... | sid, squeeze, wheezy |
| php-gettext | TEMP-0000000-07A77D | php-gettext XSS | sid, squeeze, wheezy |
| php-htmlpurifier | TEMP-0000000-196897 | htmlpurifier various | squeeze |
| php5 | CVE-2006-0931 | Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other ... | sid, squeeze, wheezy |
| CVE-2006-4023 | The ip2long function in PHP 5.1.4 and earlier may incorrectly validate ... | sid, squeeze, wheezy | |
| CVE-2006-6383 | PHP 5.2.0 and 4.4 allows local users to bypass safe_mode and ... | sid, squeeze, wheezy | |
| CVE-2006-7205 | The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 ... | sid, squeeze, wheezy | |
| CVE-2007-0448 | The fopen function in PHP 5.2.0 does not properly handle invalid URI ... | sid, squeeze, wheezy | |
| CVE-2007-1413 | Buffer overflow in the snmpget function in the snmp extension in PHP ... | sid, squeeze, wheezy | |
| CVE-2007-1581 | The resource system in PHP 5.0.0 through 5.2.1 allows ... | sid, squeeze, wheezy | |
| CVE-2007-1582 | The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 ... | sid, squeeze, wheezy | |
| CVE-2007-1710 | The readfile function in PHP 4.4.4, 5.1.6, and 5.2.1 allows ... | sid, squeeze, wheezy | |
| CVE-2007-1835 | PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session ... | sid, squeeze, wheezy | |
| CVE-2007-1883 | PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows ... | sid, squeeze, wheezy | |
| CVE-2007-1890 | Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and ... | sid, squeeze, wheezy | |
| CVE-2007-3205 | The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Subhosin, ... | sid, squeeze, wheezy | |
| CVE-2007-3294 | Multiple buffer overflows in libtidy, as used in the Tidy extension ... | sid, squeeze, wheezy | |
| CVE-2007-4255 | Buffer overflow in the mSQL extension in PHP 5.2.3 allows ... | sid, squeeze, wheezy | |
| CVE-2007-4596 | The perl extension in PHP does not follow safe_mode restrictions, ... | sid, squeeze, wheezy | |
| CVE-2007-4889 | The MySQL extension in PHP 5.2.4 and earlier allows remote attackers ... | sid, squeeze, wheezy | |
| CVE-2007-5424 | The disable_functions feature in PHP 4 and 5 allows attackers to ... | sid, squeeze, wheezy | |
| CVE-2008-2666 | Multiple directory traversal vulnerabilities in PHP 5.2.6 and earlier ... | sid, squeeze, wheezy | |
| CVE-2008-4107 | The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce ... | sid, squeeze, wheezy | |
| CVE-2008-5625 | PHP 5 before 5.2.7 does not enforce the error_log safe_mode ... | sid, squeeze, wheezy | |
| CVE-2008-7002 | PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir ... | sid, squeeze, wheezy | |
| CVE-2009-3559 | ** DISPUTED ** ... | sid, squeeze, wheezy | |
| CVE-2009-4418 | The unserialize function in PHP 5.3.0 and earlier allows ... | sid, squeeze, wheezy | |
| CVE-2010-1861 | The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 ... | sid, squeeze, wheezy | |
| CVE-2010-1862 | The chunk_split function in PHP 5.2 through 5.2.13 and 5.3 through ... | sid, squeeze, wheezy | |
| CVE-2010-1868 | The (1) sqlite_single_query and (2) sqlite_array_query functions in ... | sid, squeeze, wheezy | |
| CVE-2010-1914 | The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows ... | sid, squeeze, wheezy | |
| CVE-2010-1915 | The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through ... | sid, squeeze, wheezy | |
| CVE-2010-2097 | The (1) iconv_mime_decode, (2) iconv_substr, and (3) iconv_mime_encode ... | sid, squeeze, wheezy | |
| CVE-2010-2100 | The (1) htmlentities, (2) htmlspecialchars, (3) str_getcsv, (4) ... | sid, squeeze, wheezy | |
| CVE-2010-2101 | The (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap, (5) ... | sid, squeeze, wheezy | |
| CVE-2010-2190 | The (1) trim, (2) ltrim, (3) rtrim, and (4) substr_replace functions ... | sid, squeeze, wheezy | |
| CVE-2010-3062 | mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through ... | sid, squeeze, wheezy | |
| CVE-2010-3063 | The php_mysqlnd_read_error_from_line function in the Mysqlnd extension ... | sid, squeeze, wheezy | |
| CVE-2010-3064 | Stack-based buffer overflow in the php_mysqlnd_auth_write function in ... | sid, squeeze, wheezy | |
| CVE-2010-4697 | Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 ... | squeeze | |
| CVE-2010-4699 | The iconv_mime_decode_headers function in the Iconv extension in PHP ... | squeeze | |
| CVE-2011-0420 | The grapheme_extract function in the Internationalization extension ... | sid, wheezy | |
| CVE-2011-0753 | Race condition in the PCNTL extension in PHP before 5.3.4, when a ... | squeeze | |
| CVE-2011-0755 | Integer overflow in the mt_rand function in PHP before 5.3.4 might ... | squeeze | |
| CVE-2011-1092 | Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows ... | sid, squeeze, wheezy | |
| CVE-2011-1148 | Use-after-free vulnerability in the substr_replace function in PHP ... | sid, squeeze, wheezy | |
| CVE-2011-1464 | Buffer overflow in the strval function in PHP before 5.3.6, when the ... | squeeze | |
| CVE-2011-1467 | Unspecified vulnerability in the NumberFormatter::setSymbol (aka ... | squeeze | |
| CVE-2011-1468 | Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 ... | squeeze | |
| CVE-2011-1469 | Unspecified vulnerability in the Streams component in PHP before 5.3.6 ... | squeeze | |
| CVE-2011-1470 | The Zip extension in PHP before 5.3.6 allows context-dependent ... | squeeze | |
| CVE-2011-1657 | The (1) ZipArchive::addGlob and (2) ZipArchive::addPattern functions ... | sid, squeeze, wheezy | |
| CVE-2011-3182 | PHP before 5.3.7 does not properly check the return values of the ... | squeeze | |
| CVE-2012-1171 | safemode bypass after RSHUTDOWN | sid, squeeze, wheezy | |
| CVE-2012-2336 | sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when ... | squeeze, wheezy | |
| TEMP-0000000-A7D1F4 | PHP 5.2.9 curl safe_mode & open_basedir bypass | sid, squeeze, wheezy | |
| phpmyadmin | CVE-2005-3622 | phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain ... | sid, squeeze, wheezy |
| CVE-2005-4349 | ** DISPUTED ** ... | sid, squeeze, wheezy | |
| CVE-2006-6373 | PhpMyAdmin 2.7.0-pl2 allows remote attackers to obtain sensitive ... | sid, squeeze, wheezy | |
| CVE-2007-4306 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin ... | sid, squeeze, wheezy | |
| CVE-2011-0986 | phpMyAdmin 2.11.x before 2.11.11.2, and 3.3.x before 3.3.9.1, does not ... | squeeze | |
| CVE-2011-3646 | phpmyadmin.css.php in phpMyAdmin 3.4.x before 3.4.6 allows remote ... | squeeze | |
| CVE-2011-4064 | Cross-site scripting (XSS) vulnerability in the setup interface in ... | squeeze | |
| CVE-2012-1902 | show_config_errors.php in phpMyAdmin 3.4.x before 3.4.10.2, when a ... | squeeze | |
| phppgadmin | CVE-2006-4976 | The Date Library in John Lim ADOdb Library for PHP allows remote ... | sid, squeeze, wheezy |
| phpsysinfo | CVE-2006-3360 | Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 ... | sid, squeeze, wheezy |
| pidgin | CVE-2008-2956 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| CVE-2011-3184 | The msn_httpconn_parse_data function in httpconn.c in the MSN protocol ... | squeeze | |
| CVE-2012-1257 | sid, squeeze, wheezy | ||
| pilot-qof | CVE-2008-4997 | ** DISPUTED ** ... | squeeze |
| poppler | CVE-2010-0206 | xpdf: Invalid pointer dereference by processing JBIG2 PDF stream objects | sid, squeeze, wheezy |
| CVE-2010-0207 | xpdf: XRef table parsing infinite loop | sid, squeeze, wheezy | |
| postfix | CVE-2008-4977 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| ppp | CVE-2008-5366 | The postinst script in ppp 2.4.4rel on Debian GNU/Linux allows local ... | sid, squeeze, wheezy |
| CVE-2008-5367 | ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to ... | sid, squeeze, wheezy | |
| printfilters-ppd | CVE-2008-5034 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| pure-ftpd | CVE-2011-0418 | The glob implementation in Pure-FTPd before 1.0.32, and in libc in ... | squeeze |
| putty | CVE-2011-4607 | http://seclists.org/oss-sec/2011/q4/500 | squeeze |
| python-defaults | CVE-2008-4108 | Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) ... | sid, squeeze, wheezy |
| python-django | CVE-2007-5828 | ** DISPUTED ** ... | sid, squeeze, wheezy |
| python2.5 | CVE-2007-4559 | Directory traversal vulnerability in the (1) extract and (2) ... | squeeze |
| CVE-2011-4940 | python: potential XSS in SimpleHTTPServer's list_directory() | squeeze, sid, squeeze, wheezy | |
| python2.6 | CVE-2012-1150 | sid, squeeze, wheezy | |
| TEMP-0615118-2DDE11 | python2.6: distutils world-readable password | sid, squeeze, wheezy | |
| python2.7 | CVE-2010-3492 | The asyncore module in Python before 3.2 does not properly handle ... | sid, wheezy |
| CVE-2012-1150 | sid, wheezy | ||
| TEMP-0615118-2DDE11 | python2.6: distutils world-readable password | sid, wheezy | |
| python3.1 | CVE-2010-3492 | The asyncore module in Python before 3.2 does not properly handle ... | squeeze, sid, wheezy |
| python3.2 | CVE-2012-1150 | sid, wheezy | |
| qmail | CVE-2011-1431 | The STARTTLS implementation in qmail-smtpd.c in qmail-smtpd in the ... | sid, squeeze, wheezy |
| qt4-x11 | CVE-2008-4724 | Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome ... | sid, squeeze, wheezy |
| CVE-2009-3015 | QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and ... | sid, squeeze, wheezy | |
| CVE-2009-3272 | Stack consumption vulnerability in WebKit.dll in WebKit in Apple ... | sid, squeeze, wheezy | |
| CVE-2010-1729 | WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, ... | sid, squeeze, wheezy | |
| TEMP-0560108-565B70 | browser-based css info disclosure | sid, squeeze, wheezy | |
| TEMP-0568486-B6FCB6 | browser javascript document.write denial-of-service | sid, squeeze, wheezy | |
| rails | CVE-2010-3299 | ruby on rails: padding oracle attack | sid, squeeze, wheezy |
| CVE-2011-3187 | The to_s method in ... | sid, squeeze, wheezy | |
| request-tracker3.8 | CVE-2011-1007 | Best Practical Solutions RT before 3.8.9 does not perform certain ... | squeeze |
| rhythmbox | CVE-2008-7185 | GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of ... | sid, squeeze, wheezy |
| rpm | CVE-2010-2198 | lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the ... | sid, squeeze, wheezy |
| CVE-2010-2199 | lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the ... | sid, squeeze, wheezy | |
| samba | CVE-2010-1635 | The chain_reply function in process.c in smbd in Samba before 3.4.8 ... | sid, squeeze, wheezy |
| CVE-2010-1642 | The reply_sesssetup_and_X_spnego function in sesssetup.c in smbd in ... | sid, squeeze, wheezy | |
| serendipity | CVE-2007-1326 | SQL injection vulnerability in index.php in Serendipity 1.1.1 allows ... | sid, squeeze |
| shadow | CVE-2007-5686 | initscripts in rPath Linux 1 sets insecure permissions for the ... | sid, squeeze, wheezy |
| simgear | CVE-2009-3560 | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, ... | sid, squeeze, wheezy |
| CVE-2009-3720 | The updatePosition function in lib/xmltok_impl.c in libexpat in Expat ... | sid, squeeze, wheezy | |
| slim | TEMP-0537604-F35BD7 | insecure tmp file vulnerability in slim | sid, squeeze, wheezy |
| smarty | CVE-2007-2326 | Multiple PHP remote file inclusion vulnerabilities in HYIP Manager Pro ... | squeeze, wheezy |
| TEMP-0000000-2C7EFD | incorrect handling of {$smarty.template} and {$smarty.current_dir} | squeeze, wheezy, sid, squeeze, wheezy | |
| smsclient | CVE-2008-5155 | mail2sms.sh in smsclient 2.0.8z allows local users to overwrite ... | sid, squeeze, wheezy |
| TEMP-0498901-F99C05 | unsafe use of tempfile in ssmclient | sid, squeeze, wheezy | |
| spip | TEMP-0646758-12F1BD | spip path disclosure | squeeze |
| sql-ledger | CVE-2007-0667 | The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and ... | sid, squeeze, wheezy |
| CVE-2007-1329 | Directory traversal vulnerability in SQL-Ledger, and LedgerSMB before ... | sid, squeeze, wheezy | |
| CVE-2007-1923 | (1) LedgerSMB and (2) DWS Systems SQL-Ledger implement access control ... | sid, squeeze, wheezy | |
| CVE-2007-5372 | Multiple SQL injection vulnerabilities in (a) LedgerSMB 1.0.0 through ... | sid, squeeze, wheezy | |
| CVE-2008-4077 | The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) ... | sid, squeeze, wheezy | |
| CVE-2008-4078 | SQL injection vulnerability in the AR/AP transaction report in (1) ... | sid, squeeze, wheezy | |
| CVE-2009-3580 | Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger ... | sid, squeeze, wheezy | |
| CVE-2009-3581 | Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger ... | sid, squeeze, wheezy | |
| CVE-2009-3582 | Multiple SQL injection vulnerabilities in the delete subroutine in ... | sid, squeeze, wheezy | |
| CVE-2009-3583 | Directory traversal vulnerability in the Preferences menu item in ... | sid, squeeze, wheezy | |
| CVE-2009-3584 | SQL-Ledger 2.8.24 does not set the secure flag for the session cookie ... | sid, squeeze, wheezy | |
| CVE-2009-4402 | The default configuration of SQL-Ledger 2.8.24 allows remote attackers ... | sid, squeeze, wheezy | |
| squid | CVE-2009-0801 | Squid, when transparent interception mode is enabled, uses the HTTP ... | sid, squeeze, wheezy, sid, squeeze, wheezy |
| ssmtp | CVE-2004-0423 | The log_event function in ssmtp 2.50.6 and earlier allows local users ... | sid, squeeze, wheezy |
| CVE-2008-7258 | ** DISPUTED ** ... | sid, squeeze, wheezy | |
| suckless-tools | CVE-2012-1620 | slock screen unlocking | sid, squeeze, wheezy |
| sudo | CVE-2005-1119 | Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary ... | sid, squeeze, wheezy |
| sun-java6 | CVE-2007-0012 | Sun JRE 5.0 before update 14 allows remote attackers to cause a denial ... | squeeze |
| CVE-2007-5019 | Buffer overflow in the Sun Java Web Start ActiveX control in Java ... | squeeze | |
| sylpheed | CVE-2007-1267 | Sylpheed 2.2.7 and earlier does not properly use the --status-fd ... | sid, squeeze, wheezy |
| sysklogd | CVE-2006-1624 | The default configuration of syslogd in the Linux sysklogd package ... | sid, squeeze, wheezy |
| TEMP-0281448-00272A | Format string bug in sysklogd's syslog_tst sources | sid, squeeze, wheezy | |
| systemtap | CVE-2011-1769 | SystemTap 1.4 and earlier, when unprivileged (aka stapusr) mode is ... | squeeze |
| sysvinit | TEMP-0517018-A83CE6 | sysvinit: no-root option in expert installer exposes locally exploitable security flaw | sid, squeeze, wheezy |
| tar | CVE-2005-2541 | Tar 1.15.1 does not properly warn the user when extracting setuid or ... | sid, squeeze, wheezy |
| TEMP-0290435-0B57B5 | tar's rmt command may have undesired side effects | sid, squeeze, wheezy | |
| thttpd | CVE-2009-4491 | thttpd 2.25b0 writes data to a log file without sanitizing ... | squeeze |
| thunar | TEMP-0517020-915121 | thunar: potential exploits via application launchers | sid, squeeze, wheezy |
| tiff | CVE-2008-1586 | ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod ... | sid, squeeze, wheezy |
| CVE-2010-2595 | The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ... | sid, squeeze, wheezy | |
| CVE-2010-2596 | The OJPEGPostDecode function in tif_ojpeg.c in LibTIFF 3.9.0 and ... | sid, squeeze, wheezy | |
| CVE-2010-2597 | The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 ... | sid, squeeze, wheezy | |
| CVE-2010-2598 | LibTIFF in Red Hat Enterprise Linux (RHEL) 3 on x86_64 platforms, as ... | sid, squeeze, wheezy | |
| CVE-2010-2630 | The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly ... | sid, squeeze, wheezy | |
| CVE-2010-2631 | LibTIFF 3.9.0 ignores tags in certain situations during the first ... | sid, squeeze, wheezy | |
| tinymux | CVE-2007-1959 | Unspecified vulnerability in the process_cmdent function in ... | sid, squeeze, wheezy |
| tomcat6 | CVE-2010-4312 | The default configuration of Apache Tomcat 6.x does not include the ... | sid, squeeze, wheezy |
| tor | CVE-2006-6893 | Tor allows remote attackers to discover the IP address of a hidden ... | sid, squeeze, wheezy |
| CVE-2007-1103 | Tor does not verify a node's uptime and bandwidth advertisements, ... | sid, squeeze, wheezy | |
| CVE-2009-0654 | Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote ... | sid, squeeze, wheezy | |
| varnish | CVE-2009-4488 | ** DISPUTED ** Varnish 2.0.6 writes data to a log file without ... | sid, squeeze, wheezy |
| vdr | CVE-2010-3387 | ** DISPUTED ** ... | squeeze |
| vim | CVE-2008-4677 | autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions ... | sid, squeeze, wheezy |
| vino | CVE-2011-1164 | sid, squeeze, wheezy | |
| CVE-2011-1165 | sid, squeeze, wheezy | ||
| vlc | CVE-2012-2396 | VideoLAN VLC media player 2.0.1 allows remote attackers to cause a ... | sid, squeeze, wheezy |
| vte | CVE-2005-0023 | gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to ... | sid, squeeze, wheezy |
| w3m | TEMP-0532514-9137E0 | predictable random number generator used in web browsers | sid, squeeze, wheezy |
| webkit | CVE-2008-7246 | Google Chrome 0.2.149.29 and earlier allows remote attackers to cause ... | sid, squeeze, wheezy |
| CVE-2009-1514 | Google Chrome 1.0.154.53 allows remote attackers to cause a denial of ... | sid, squeeze, wheezy | |
| CVE-2009-2578 | Google Chrome 2.x through 2.0.172 allows remote attackers to cause a ... | sid, squeeze, wheezy | |
| CVE-2009-2953 | Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote ... | sid, squeeze, wheezy | |
| CVE-2009-2955 | Google Chrome 1.0.154.48 and earlier allows remote attackers to cause ... | sid, squeeze, wheezy | |
| CVE-2009-3011 | Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and ... | sid, squeeze, wheezy | |
| CVE-2009-3015 | QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and ... | sid, squeeze, wheezy | |
| CVE-2009-3268 | Google Chrome 1.0.154.48 and earlier allows remote attackers to cause ... | sid, squeeze, wheezy | |
| CVE-2009-3272 | Stack consumption vulnerability in WebKit.dll in WebKit in Apple ... | sid, squeeze, wheezy | |
| CVE-2010-1131 | JavaScriptCore.dll, as used in Apple Safari 4.0.5 on Windows XP SP3, ... | sid, squeeze, wheezy | |
| CVE-2010-1180 | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers ... | sid, squeeze, wheezy | |
| CVE-2010-1181 | Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers ... | sid, squeeze, wheezy | |
| CVE-2010-1384 | Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and ... | sid, squeeze, wheezy | |
| CVE-2010-1729 | WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, ... | sid, squeeze, wheezy | |
| CVE-2010-1992 | Google Chrome 1.0.154.48 executes a mail application in situations ... | sid, squeeze, wheezy | |
| CVE-2010-2120 | Google Chrome 1.0.154.48 allows remote attackers to cause a denial of ... | sid, squeeze, wheezy | |
| CVE-2010-4482 | Unspecified vulnerability in Google Chrome before 8.0.552.215 allows ... | sid, squeeze, wheezy | |
| CVE-2010-4485 | Google Chrome before 8.0.552.215 does not properly restrict the ... | sid, squeeze, wheezy | |
| CVE-2011-1194 | Multiple unspecified vulnerabilities in Google Chrome before ... | sid, squeeze, wheezy | |
| CVE-2011-1304 | Unspecified vulnerability in Google Chrome before 11.0.696.57 allows ... | sid, squeeze, wheezy | |
| CVE-2011-4691 | Google Chrome 15.0.874.121 and earlier does not prevent capture of ... | sid, squeeze, wheezy | |
| CVE-2011-4692 | WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 ... | sid, squeeze, wheezy | |
| TEMP-0560108-565B70 | browser-based css info disclosure | sid, squeeze, wheezy | |
| TEMP-0568486-B6FCB6 | browser javascript document.write denial-of-service | sid, squeeze, wheezy | |
| wget | CVE-2006-6719 | The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) ... | sid, squeeze, wheezy |
| wicd | CVE-2012-0813 | wicd cleartext passwords | squeeze |
| wireshark | CVE-2011-1142 | Stack consumption vulnerability in the dissect_ber_choice function in ... | squeeze |
| CVE-2011-1143 | epan/dissectors/packet-ntlmssp.c in the NTLMSSP dissector in Wireshark ... | squeeze | |
| CVE-2011-2597 | The Lucent/Ascend file parser in Wireshark 1.2.x before 1.2.18, 1.4.x ... | squeeze | |
| CVE-2011-2698 | Off-by-one error in the elem_cell_id_aux function in ... | squeeze | |
| CVE-2011-3266 | The proto_tree_add_item function in Wireshark 1.6.0 through 1.6.1 and ... | squeeze | |
| CVE-2011-4101 | The dissect_infiniband_common function in ... | squeeze | |
| CVE-2012-1593 | epan/dissectors/packet-ansi_a.c in the ANSI A dissector in Wireshark ... | squeeze | |
| CVE-2012-1594 | epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in ... | squeeze | |
| CVE-2012-1596 | The mp2t_process_fragmented_payload function in ... | squeeze | |
| wordpress | CVE-2006-0733 | ** DISPUTED ** Cross-site scripting (XSS) vulnerability in WordPress ... | sid, squeeze, wheezy |
| CVE-2008-0191 | WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive ... | sid, squeeze, wheezy | |
| CVE-2012-0937 | ** DISPUTED ** wp-admin/setup-config.php in the installation component ... | sid, squeeze, wheezy | |
| TEMP-0500295-A176F7 | possible script injection via /etc/wordpress/wp-config.php | sid, squeeze, wheezy | |
| xerces-c2 | CVE-2008-4482 | The XML parser in Xerces-C++ before 3.0.0 allows context-dependent ... | sid, squeeze, wheezy |
| xfig | CVE-2009-4228 | Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and ... | sid, squeeze, wheezy |
| xine-lib | CVE-2008-5247 | The real_parse_audio_specific_data function in demux_real.c in ... | sid, squeeze, wheezy |
| xloadimage | CVE-2006-4484 | Buffer overflow in the LWZReadByte_ function in ... | sid, squeeze, wheezy |
| xpdf | CVE-2010-0206 | xpdf: Invalid pointer dereference by processing JBIG2 PDF stream objects | sid, squeeze, wheezy |
| CVE-2010-0207 | xpdf: XRef table parsing infinite loop | sid, squeeze, wheezy | |
| TEMP-0000000-2EA6C5 | NULL dereferences, similar to Adobe's CVE-2009-0658 | sid, squeeze, wheezy | |
| xterm | CVE-2006-4447 | X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, ... | sid, squeeze, wheezy |
| xview | CVE-2005-4796 | Unspecified vulnerability in the XView library (libxview.so) in ... | sid, squeeze, wheezy |
| yaws | CVE-2009-4495 | Yaws 1.85 writes data to a log file without sanitizing non-printable ... | sid, squeeze, wheezy |
| yui | CVE-2007-2385 | The Yahoo! UI framework exchanges data using JavaScript Object ... | sid, squeeze, wheezy |
| CVE-2010-4710 | Cross-site scripting (XSS) vulnerability in the addItem method in the ... | sid, squeeze, wheezy | |
| zabbix | CVE-2011-3264 | Zabbix before 1.8.6 allows remote attackers to obtain sensitive ... | squeeze |
Home - Testing Security Team - Debian Security - Source (SVN)