Some issues have not been assigned CVE names, but are still tracked by this database. In this case, the system automatically assigns a unique name. These names are not stable and can change when the database is updated, so they should not be used in external references.
The automatically generated names come in two flavors:
the first kind starts with the string "TEMP-000000-". This means that no Debian bug has been assigned to this
issue (or a bug has been created and is not recorded in this database).
In the second kind of names, there is a Debian bug for the issue, and the "000000"part of the name is replaced with the
Debian bug number.
| Bug | Description |
|---|---|
| TEMP-0000000-01B8B3 | GHSA-c5gr-hmqp-pwj4: RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard |
| TEMP-0000000-02046B | GHSA-v649-94v2-p72q: Uninitialised heap disclosure in FreeRDP Save Session Info PDU |
| TEMP-0000000-027680 | GHSA-ffjr-p229-hpch: NULL pointer dereference in gdi_surface_bits when the client has not enabled NSCodec |
| TEMP-0000000-035231 | TROVE-2026-018 |
| TEMP-0000000-04317D | GHSA-vccg-35r5-8jrf: Stream_EnsureCapacity still overflows |
| TEMP-0000000-07A77D | php-gettext XSS |
| TEMP-0000000-0DF650 | GHSA-hw7p-5h2r-83gq: Disclosure of uninitialized heap memory in the urbdrc USB redirection path |
| TEMP-0000000-11FDF8 | RUSTSEC-2023-0074 |
| TEMP-0000000-137F0A | quoteless attributes in templates can lead to content injection |
| TEMP-0000000-18F9D9 | decoder deadlock (DoS) via alpha-aux reference cycle |
| TEMP-0000000-1CA3C2 | TROVE-2026-033 |
| TEMP-0000000-1DDFF5 | GHSA-q65v-4w7q-hx3r: Smartcard response lengths are not bounded to their inline ATR arrays |
| TEMP-0000000-1DE636 | GHSA-57h7-vw2f-2f9x: Client-side heap OOB read in FreeRDP AVC444 chroma combine |
| TEMP-0000000-1ED20C | Out-of-bounds read in RGB-YCbCr identity-matrix colour conversion with mismatched per-channel bit depths |
| TEMP-0000000-1F4FF2 | Heap buffer overflow in SVT-AV1 encoder for high-bit-depth alpha channels |
| TEMP-0000000-205CFB | GHSA-r7jx-j9h7-j4xj: FreeRDP RDPGFX ResetGraphics discloses up to 300 bytes of uninitialized heap memory |
| TEMP-0000000-205E00 | RUSTSEC-2026-0109 |
| TEMP-0000000-254611 | TROVE-2026-020 |
| TEMP-0000000-276532 | RUSTSEC-2026-0213 |
| TEMP-0000000-2BCF00 | GHSA-9jcm-x588-gh26: SHOW_PROTOCOL live-pointer overwrite |
| TEMP-0000000-324AE3 | heap OOB read / info disclosure (Op_YCbCr420_to_RRGGBBaa |
| TEMP-0000000-345A3B | handlebars: quoteless attributes in templates can lead to content injection |
| TEMP-0000000-3A226A | RUSTSEC-2023-0018 |
| TEMP-0000000-3A69B8 | arbitrary code execution upon opening file |
| TEMP-0000000-3E88C4 | GHSA-h5w2-q35j-443h: Out-of-bounds write in urb_send_current_frame_number_result |
| TEMP-0000000-40DFCF | WSA-2026-11: Logger: Write of logger file outside of configured path |
| TEMP-0000000-42E2A2 | GHSA-f5p6-88mh-59vg: audin Apple backends perform overflow-prone buffer size arithmetic from server-controlled values |
| TEMP-0000000-441D30 | RUSTSEC-2026-0122 |
| TEMP-0000000-4578D8 | znuny: Missing HTTP headers for attachments |
| TEMP-0000000-4D5947 | WSA-2026-3: irc: Missing size limit for the unterminated IRC message or isupport value (message 005) |
| TEMP-0000000-4E708C | TROVE-2026-016 |
| TEMP-0000000-51E97C | RUSTSEC-2026-0097 |
| TEMP-0000000-539702 | TROVE-2026-042 |
| TEMP-0000000-53D7AE | RUSTSEC-2026-0145 |
| TEMP-0000000-5A4286 | GHSA-wmpc-m6g9-fwj8: relay: Memory leak in API relay, endpoint "handshake" |
| TEMP-0000000-5D7F62 | RUSTSEC-2025-0168 |
| TEMP-0000000-5DEDAF | RUSTSEC-2026-0112 |
| TEMP-0000000-5E8928 | sogo issues from 5.12.10 |
| TEMP-0000000-63C355 | RUSTSEC-2025-0143 |
| TEMP-0000000-66FC9C | RUSTSEC-2024-0332: Degradation of service in h2 servers with CONTINUATION Flood |
| TEMP-0000000-6F5D6B | WSA-2026-6: xfer: Write of DCC file received outside of configured download path |
| TEMP-0000000-6FDF96 | TROVE-2026-034 |
| TEMP-0000000-72CE9B | WSA-2026-7: xfer: Buffer overflow when receiving a line in a Xfer chat (DCC chat) buffer |
| TEMP-0000000-72DB32 | RUSTSEC-2026-0222 |
| TEMP-0000000-73CA4D | TROVE-2026-043 |
| TEMP-0000000-740209 | GHSA-pj8w-fh79-f438: rts_read_result length-checks 2 bytes and then reads 4 |
| TEMP-0000000-78A5AA | RUSTSEC-2026-0119 |
| TEMP-0000000-7F4255 | RCE fixed in 4.4.23 |
| TEMP-0000000-812972 | GHSA-4464-r7qj-pgrx: FreeRDP: server stores client Core Data DesktopWidth/Height unvalidated in GCC negotiation |
| TEMP-0000000-8E2D4B | GHSA-23pf-q83q-x45r: Unbounded MonitorIds used as an array index in X11 monitor selection |
| TEMP-0000000-8FA4DB | GHSA-m85m-3qxv-63h5: Infinite loop / CPU DoS in pool_decode_rect |
| TEMP-0000000-905912 | Heap buffer overflow in unci mixed-interleave decoding with unequal chroma bit depths |
| TEMP-0000000-95CBBF | uudecode: stack out of bounds read access |
| TEMP-0000000-9C2340 | GHSA-j5mq-3349-gwmm: channels,smartcard worker creation failure frees a devman-owned device |
| TEMP-0000000-9D9504 | tryton-server: Python code execution via uploaded templates |
| TEMP-0000000-A0AD39 | TROVE-2026-036 |
| TEMP-0000000-A510E8 | RUSTSEC-2026-0104 |
| TEMP-0000000-A6FE70 | TROVE-2026-040 |
| TEMP-0000000-A7B0B9 | RCE fixed in 4.4.22 |
| TEMP-0000000-A954ED | RUSTSEC-2026-0135 |
| TEMP-0000000-ACBC4C | buffer overflows in init_cups |
| TEMP-0000000-B1CD0A | WSA-2026-4: relay: Missing size limit for the received websocket frame, HTTP message and HTTP body |
| TEMP-0000000-B20F11 | RUSTSEC-2026-0234 |
| TEMP-0000000-B26F1D | WSA-2026-8: relay: Buffer overflow in dump of Relay data |
| TEMP-0000000-B32316 | TROVE-2026-004 |
| TEMP-0000000-B5A5F9 | RUSTSEC-2026-0136 |
| TEMP-0000000-B96FAD | RUSTSEC-2025-0005: Out of bounds write triggered by crafted coverage data |
| TEMP-0000000-BB5891 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and Double Free in libde265 |
| TEMP-0000000-C0BE35 | RUSTSEC-2026-0183 |
| TEMP-0000000-C0C4D6 | GHSA-w9qg-g24r-77f6: URBDRC/libusb control-transfer path aborts on reachable OutputBufferSize assertion |
| TEMP-0000000-C525DA | GHSA-x7v6-xfx3-52j6: FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS |
| TEMP-0000000-CF89FB | RUSTSEC-2026-0005: Potential use-after-free in oneshot when used asynchronously |
| TEMP-0000000-D02C9B | TROVE-2026-013 |
| TEMP-0000000-D22263 | Heap-buffer-overflow read in uncompressed (`uncv`) HEIF sequence RGB conversion for odd-height 4:2:0 frames |
| TEMP-0000000-D34B97 | RUSTSEC-2026-0134 |
| TEMP-0000000-D426B9 | TROVE-2026-014 |
| TEMP-0000000-D512DA | RUSTSEC-2026-0233 |
| TEMP-0000000-D99B95 | TROVE-2026-035 |
| TEMP-0000000-DA2DA0 | RUSTSEC-2026-0269 |
| TEMP-0000000-DD1424 | RUSTSEC-2023-0041 |
| TEMP-0000000-DF359B | GHSA-hg4r-vv53-vwf8: URBDRC out-of-bounds read in func_get_ep_desc via InterfaceNumber/array-position index mismatch |
| TEMP-0000000-E66AA0 | heap-use-after-free in decoder_context::reset() via dangling previous_slice_header |
| TEMP-0000000-E81ECD | RUSTSEC-2026-0113 |
| TEMP-0000000-E970CB | RUSTSEC-2026-0204 |
| TEMP-0000000-EC2CDF | RUSTSEC-2026-0235 |
| TEMP-0000000-EF7B0A | RUSTSEC-2026-0184 |
| TEMP-0000000-F1FB58 | WSA-2026-5: irc: Buffer overflow when receiving a DCC file |
| TEMP-0000000-F2843E | RUSTSEC-2026-0137 |
| TEMP-0000000-F43378 | GHSA-6mpx-c8rj-whj5: FreeRDP server DRDYNVC parser use-after-free during concurrent channel close |
| TEMP-0000000-F5DC1F | TROVE-2026-015 |
| TEMP-0000000-F7A20F | Kernel: Unprivileged user can freeze journald |
| TEMP-0000000-F89685 | GHSA-r9pv-ffph-6gg6: Heap buffer overflow in nego_send_negotiation_request via oversized LB_LOAD_BALANCE_INFO routing token |
| TEMP-0000000-F971FC | TROVE-2025-015 |
| TEMP-0000000-FBC245 | GHSA-2vf2-grvj-6g8x: Heap buffer overflow in nego_send_negotiation_request |
| TEMP-0290435-0B57B5 | tar's rmt command may have undesired side effects |
| TEMP-0517018-A83CE6 | sysvinit: no-root option in expert installer exposes locally exploitable security flaw |
| TEMP-0517020-915121 | thunar: potential exploits via application launchers |
| TEMP-0528250-2E3658 | hex-a-hop: buffer overflow in loading save games |
| TEMP-0532514-9137E0 | predictable random number generator used in web browsers |
| TEMP-0537604-F35BD7 | insecure tmp file vulnerability in slim |
| TEMP-0560108-565B70 | browser-based css info disclosure |
| TEMP-0601525-BEBB65 | libgd2: gdImageColorTransparent can write outside buffer |
| TEMP-0608980-E8B8DF | Crash with long HOME environment variable |
| TEMP-0628843-DBAD28 | more related to CVE-2005-4890 |
| TEMP-0772585-D41D8C | |
| TEMP-0841856-B18BAF | Privilege escalation possible to other user than root |
| TEMP-1031542-93CC2D | XSS Vulnerability in matrix.pl |
| TEMP-1036689-1CA7FB | Block themes parsing shortcodes in user-generated data |
| TEMP-1050299-7F4591 | RUSTSEC-2023-0052 webpki: CPU denial of service in certificate path building |
| TEMP-1051808-528792 | RUSTSEC-2023-0059: Unaligned read of *const *const c_char pointer |
| TEMP-1082053-F368BB | RUSTSEC-2023-0086 |
| TEMP-1103894-9182BD | RUSTSEC-2025-0020 |
| TEMP-1103988-584961 | RUSTSEC-2025-0023 |
| TEMP-1104554-71A417 | Integer overflow with decimal numbers in calculation of expression |
| TEMP-1104554-A4A19A | Buffer overflow in parsing of date/time |
| TEMP-1104554-B16504 | Integer overflow in base32 decode/encode functions |
| TEMP-1104554-D19F68 | Buffer overflow in range of chars in evaluated expressions |
| TEMP-1104554-D6608C | Integer overflow in conversion of version to an integer |
| TEMP-1104554-F3166C | Buffer overflow in base 32 encoding in evaluated expressions |
| TEMP-1108942-E3F85E | exposes .zip passwords while (un)archiving |
| TEMP-1111689-27EE99 | OSSN-0094 |
| TEMP-1111844-CF9125 | qemu: stop using C (Credentials) flag for binfmt_misc registration |
| TEMP-1112471-76797E | RUSTSEC-2025-0051 |
| TEMP-1115977-4FD111 | RUSTSEC-2025-0071 |
| TEMP-1122195-D08402 | RUSTSEC-2025-0132 |
| TEMP-1124688-97C512 | RUSTSEC-2026-0001 |
| TEMP-1127315-BE4F15 | RUSTSEC-2026-0008 |
| TEMP-1133085-EC036F | RUSTSEC-2026-0049 |
| TEMP-1134947-DEEDE9 | RUSTSEC-2026-0111 |
| TEMP-1138849-FDBA9E | Mistral workflow execution context exposes Keystone auth token |
| TEMP-1139875-06D14E | RUSTSEC-2026-0177 |
| TEMP-1139876-2010E8 | RUSTSEC-2026-0180 |
| TEMP-1139876-F3C684 | RUSTSEC-2026-0179 |
| TEMP-1139877-7225AC | RUSTSEC-2026-0172 |
| TEMP-1139958-1B9A8F | RUSTSEC-2026-0174 |
| TEMP-1140011-71A42A | RUSTSEC-2026-0176 |
| TEMP-1140013-2F2A60 | RUSTSEC-2026-0178 |
| TEMP-1141479-B41609 | RUSTSEC-2026-0186 |
| TEMP-1141480-CFE925 | RUSTSEC-2026-0187 |
| TEMP-1141588-A0ECB3 | RUSTSEC-2026-0195 |
| TEMP-1141589-7C4D9A | RUSTSEC-2026-0197 |
| TEMP-1141591-1B9DBD | RUSTSEC-2026-0202 |
| TEMP-1141592-7AFE09 | RUSTSEC-2026-0166 |
| TEMP-1141593-8B5C26 | RUSTSEC-2026-0190 |
| TEMP-1141594-38CB0B | RUSTSEC-2026-0193 |
| TEMP-1141595-863BDB | RUSTSEC-2026-0194 |
| TEMP-1141625-A16007 | InspIRCd Security Advisory 2026-01 |
| TEMP-1142113-1BFB50 | Nova console WebSocket proxy Origin allow-list poisoning |
| TEMP-1142597-FFA22A | GHSA-68ff-gq39-pqjm: relay: authentication bypass with the "plain" password hash algorithm |
| TEMP-1142894-2C375F | GHSA-q2xg-9ggx-77mr: Stack buffer overflow in irc_message_split_join when building a JOIN with keys |
| TEMP-1142894-B589E0 | GHSA-hx59-4hq9-6vmw: relay: use-after-free and double free when a remote relay sends an event with an array as body |
| TEMP-1142894-D4016A | GHSA-rfmh-3r7f-jpx5: Use-after-free in the irc plugin when a batched message disconnects the server |
| TEMP-1142904-117334 | heap OOB read in EF_IZUNIX3 extra field handler |
| TEMP-1142905-081994 | stack out-of-bounds NUL write in EF_SMARTZIP handler |
| TEMP-1142906-2C6C79 | heap buffer overflow WRITE in memextract() STORED path |
| TEMP-1142937-657D95 | Neutron sub-resource APIs do not verify parent ownership |
| TEMP-1143114-235E9E | RUSTSEC-2024-0429 |
| TEMP-1143804-40DE70 | OSSN-0103 |
| TEMP-1143866-6DBA82 | Command injection issue with zip |
| TEMP-1144105-8C4D6A | GHSA-7cgc-gp99-6jmm: resource exhaustion via LZMA decoding |
| TEMP-1144106-D6004A | GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems |
| TEMP-1144130-0EF88B | GHSA-v2gw-v9h5-9q4x |
| TEMP-1144130-40A79A | GHSA-8qxj-x646-phcm |
| TEMP-1144130-44EC0B | GHSA-qrwq-7qwx-q9rp |
| TEMP-1144130-71598F | GHSA-w69g-9x8j-7p8f |
| TEMP-1144130-80BBC5 | GHSA-fqx6-vh4p-42cg |
| TEMP-1144130-973A49 | GHSA-jr92-2v97-wgvc |
| TEMP-1144130-B3D5FC | GHSA-q4gr-vc25-57m5 |
| TEMP-1144130-BEF59A | GHSA-9rww-v4mm-x4jg |
| TEMP-1144130-FF3646 | GHSA-99wv-m8rp-g58x |
| TEMP-1144214-4C9607 | OSSN-0106: API ramdisk endpoints require network-level access controls |
| TEMP-1144394-9DB3D2 | RUSTSEC-2026-0244 |
| TEMP-1144395-348CC4 | RUSTSEC-2026-0221 |
| TEMP-1144396-657C7A | RUSTSEC-2026-0257 |
| TEMP-1144397-AB31D3 | RUSTSEC-2026-0253 |
| TEMP-1144398-8DC6D4 | RUSTSEC-2026-0256 |
| TEMP-1144399-DAC823 | RUSTSEC-2026-0255 |
| TEMP-1144640-5ABA9D | divide-by-zero on zero glyph width causes crash |
| TEMP-1144641-391451 | out-of-bounds read through attacker-controlled property offset |
| TEMP-1144642-D02975 | out-of-bounds read in szLpstr/xstrdup may expose adjacent heap data |
| TEMP-1144643-BC29B7 | heap out-of-bounds write when appending font-table entry |
| TEMP-1144645-69C016 | heap out-of-bounds write during Unicode font-name conversion |
| TEMP-1144839-91D17B | GHSA-xrfq-jhgh-wqch: Authentication bypass in the web interface |
| TEMP-1145423-6B1E32 | heap out-of-bounds read during OLE property decoding |
| TEMP-1145563-076BF6 | GHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows configuration takeover and remote code execution |
| TEMP-1145563-F10EE7 | GHSA-75g3-96fr-7p2r: SABnzbd PAR2 path traversal enabling cross-job __verified__ pickle RCE |
| TEMP-1146838-05CD08 | `is_local_url()` bypass via trailing-dot FQDN in stylesheet URL |
| TEMP-1146838-17D26D | Zero-click stored XSS via TNEF MIME tag injection in the attachment URL |
| TEMP-1146838-184AD1 | Cross-user access in contact group membership (add/remove) in the SQL address book |
| TEMP-1146838-192392 | Remote-content blocker bypass via SVG SMIL src animation |
| TEMP-1146838-1D84E4 | XSS in the HTML editor using text/enriched part content |
| TEMP-1146838-252E75 | CSS declaration smuggling via un-encoded ampersand emission |
| TEMP-1146838-2C017C | Email header injection via identity's organization field |
| TEMP-1146838-2D86BF | CSS property injection via body `background` attribute |
| TEMP-1146838-61F931 | Remote content blocking bypass via CSS escapes in FuncIRI attributes |
| TEMP-1146838-752355 | Email header injection via bare CR in the subject field |
| TEMP-1146838-FA492B | Email header injection via C-escape \r in the recipient display name |
| TEMP-1147154-EA5624 | GHSA-q326-jpxx-jmjc: __wrapped__ dispatch bypass allows unauthenticated API access |
| TEMP-1147154-ECE4C7 | GHSA-mjwj-v5mr-cmcg: PAR2 symlink bypass allows pickle remote code execution. |
| TEMP-1147318-639065 | GHSA-5qpq-xqfv-j9pg: Invalid write if a decoder is reinitialized after allocation failure |
| TEMP-1147701-003AAD | GHSA-484h-v688-jq5j: Source URL scheme bypasses sandboxed mode protections across multiple source subtypes |
| Bug | Description |
|---|---|
| TEMP-0000000-00657F | pure-ftpd-mysql: any problems with a home dir will allow rw to the entire filesystem |
| TEMP-0000000-018938 | SQL Injection in host_templates.php |
| TEMP-0000000-01B8B3 | GHSA-c5gr-hmqp-pwj4: RDPDR out-of-bounds read in rdpdr_dump_packet via UINT32 wraparound in 16 + computerNameLen guard |
| TEMP-0000000-01E656 | Possible SQL injection in freeradius |
| TEMP-0000000-02046B | GHSA-v649-94v2-p72q: Uninitialised heap disclosure in FreeRDP Save Session Info PDU |
| TEMP-0000000-027680 | GHSA-ffjr-p229-hpch: NULL pointer dereference in gdi_surface_bits when the client has not enabled NSCodec |
| TEMP-0000000-02F7AB | file descriptor leak when a Compose file uses the "include" directive |
| TEMP-0000000-02FC6A | RUSTSEC-2026-0268 |
| TEMP-0000000-035231 | TROVE-2026-018 |
| TEMP-0000000-04317D | GHSA-vccg-35r5-8jrf: Stream_EnsureCapacity still overflows |
| TEMP-0000000-0477AA | get_groups does not always returns the group of the action |
| TEMP-0000000-050E10 | mailutils: sql injection vulnerability in sql authentication module |
| TEMP-0000000-076325 | RUSTSEC-2023-0035: enumflags2: Adverserial use of make_bitflags! macro can cause undefined behavior |
| TEMP-0000000-09234C | insecure usage of temporary files in flash-kernel |
| TEMP-0000000-0999A8 | syslog-ng dos |
| TEMP-0000000-099EAC | werkzeug hashes its secret instead of using hmac |
| TEMP-0000000-0CA7E3 | XSS in press-this of wordpress |
| TEMP-0000000-0DF650 | GHSA-hw7p-5h2r-83gq: Disclosure of uninitialized heap memory in the urbdrc USB redirection path |
| TEMP-0000000-0EB5E1 | node-d3-color redos |
| TEMP-0000000-0F8B2E | RUSTSEC-2022-0094 |
| TEMP-0000000-106DD8 | linux-ftpd: null ptr dereference |
| TEMP-0000000-11FDF8 | RUSTSEC-2023-0074 |
| TEMP-0000000-15DB04 | RUSTSEC-2024-0359 |
| TEMP-0000000-18F9D9 | decoder deadlock (DoS) via alpha-aux reference cycle |
| TEMP-0000000-1926D8 | RUSTSEC-2025-0042 |
| TEMP-0000000-196897 | htmlpurifier various |
| TEMP-0000000-19B927 | Partial SMAP bypass on 64-bit Linux kernels |
| TEMP-0000000-1BAE4D | GNUTLS-SA-2016-2: certificate verification issue |
| TEMP-0000000-1CA3C2 | TROVE-2026-033 |
| TEMP-0000000-1CC548 | Cross-site scripting (XSS) vulnerability in cgit's "txt2html" filter |
| TEMP-0000000-1DDFF5 | GHSA-q65v-4w7q-hx3r: Smartcard response lengths are not bounded to their inline ATR arrays |
| TEMP-0000000-1DE636 | GHSA-57h7-vw2f-2f9x: Client-side heap OOB read in FreeRDP AVC444 chroma combine |
| TEMP-0000000-1E2093 | Linux ASLR mmap weakness: Reducing entropy by half |
| TEMP-0000000-1ED20C | Out-of-bounds read in RGB-YCbCr identity-matrix colour conversion with mismatched per-channel bit depths |
| TEMP-0000000-1F321D | BUG/MAJOR: http: don't read past buffer's end in http_replace_value |
| TEMP-0000000-1F4FF2 | Heap buffer overflow in SVT-AV1 encoder for high-bit-depth alpha channels |
| TEMP-0000000-2025B8 | Missing normalization |
| TEMP-0000000-205CFB | GHSA-r7jx-j9h7-j4xj: FreeRDP RDPGFX ResetGraphics discloses up to 300 bytes of uninitialized heap memory |
| TEMP-0000000-205E00 | RUSTSEC-2026-0109 |
| TEMP-0000000-23C1BD | Sidekiq::Web lacks CSRF protection |
| TEMP-0000000-2480C7 | RUSTSEC-2024-0404 |
| TEMP-0000000-24F61A | Enforce use of HTTPS for MathJax in IPython |
| TEMP-0000000-254611 | TROVE-2026-020 |
| TEMP-0000000-2563A0 | RUSTSEC-2026-0218 |
| TEMP-0000000-269968 | X launcher doesn't drop group privileges |
| TEMP-0000000-271E1A | vpnc: config file path security hole |
| TEMP-0000000-276532 | RUSTSEC-2026-0213 |
| TEMP-0000000-283B1A | Quassel: /var/lib/quassel/quasselCert.pem world-readable |
| TEMP-0000000-28C30A | RUSTSEC-2023-0058: Exposes reference to non-Sync data to an arbitrary thread |
| TEMP-0000000-2A36A7 | remote DoS when case of the characters of a nickname is modified |
| TEMP-0000000-2BCF00 | GHSA-9jcm-x588-gh26: SHOW_PROTOCOL live-pointer overwrite |
| TEMP-0000000-2C7EFD | incorrect handling of {$smarty.template} and {$smarty.current_dir} |
| TEMP-0000000-2D36D7 | cyassl: RSA Padding check vulnerability |
| TEMP-0000000-2D8F93 | isc-dhcp: omapi dos |
| TEMP-0000000-324AE3 | heap OOB read / info disclosure (Op_YCbCr420_to_RRGGBBaa |
| TEMP-0000000-3336BA | htdig: several unspecified security problems |
| TEMP-0000000-375947 | RUSTSEC-2022-0092 |
| TEMP-0000000-37DBC3 | use after free / double free |
| TEMP-0000000-3815A2 | Avoid unbounded SFTP extended attribute key/values |
| TEMP-0000000-3A226A | RUSTSEC-2023-0018 |
| TEMP-0000000-3A69B8 | arbitrary code execution upon opening file |
| TEMP-0000000-3D1157 | information leak in event device handling |
| TEMP-0000000-3D82DC | axel URL parser buffer overflow |
| TEMP-0000000-3E4AC3 | first_boot: Use session to verify first boot welcome step |
| TEMP-0000000-3E88C4 | GHSA-h5w2-q35j-443h: Out-of-bounds write in urb_send_current_frame_number_result |
| TEMP-0000000-3EB501 | Possible problem with insecure usage of sscanf in obexftp client |
| TEMP-0000000-3F0E00 | tor insufficient authentication on control port |
| TEMP-0000000-404599 | Multiple security problems in lbreakout2 |
| TEMP-0000000-40DFCF | WSA-2026-11: Logger: Write of logger file outside of configured path |
| TEMP-0000000-42228B | spip DoS |
| TEMP-0000000-425714 | argyll unsafe udev rules |
| TEMP-0000000-42E2A2 | GHSA-f5p6-88mh-59vg: audin Apple backends perform overflow-prone buffer size arithmetic from server-controlled values |
| TEMP-0000000-43D999 | Insecure temp files in firehol |
| TEMP-0000000-4578D8 | znuny: Missing HTTP headers for attachments |
| TEMP-0000000-4677DE | spip: XSS alowing priviledge escalation |
| TEMP-0000000-47717A | gunicorn fails to drop supplemental groups |
| TEMP-0000000-47E1CE | crashes found with afl |
| TEMP-0000000-481246 | libxslt segfault / DoS |
| TEMP-0000000-4C54C0 | atftp DoS |
| TEMP-0000000-4D5947 | WSA-2026-3: irc: Missing size limit for the unterminated IRC message or isupport value (message 005) |
| TEMP-0000000-4DA0A8 | dbus format string vulnerability |
| TEMP-0000000-4DAA44 | out of bounds reads in ASF demuxer |
| TEMP-0000000-4E21BA | xscreensaver: symlink attack enables local information disclosure |
| TEMP-0000000-4E708C | TROVE-2026-016 |
| TEMP-0000000-4E8C51 | RUSTSEC-2024-0409 |
| TEMP-0000000-4F0A4A | Access to records of report are not checked |
| TEMP-0000000-516A9E | NTFS driver for FUSE unspecified issue |
| TEMP-0000000-51E97C | RUSTSEC-2026-0097 |
| TEMP-0000000-523402 | auth bypass |
| TEMP-0000000-529D94 | RUSTSEC-2026-0199 |
| TEMP-0000000-52FF39 | dokuwiki ACL bypass |
| TEMP-0000000-5337A6 | lhasa: several directory traversal vulnerabilities |
| TEMP-0000000-539702 | TROVE-2026-042 |
| TEMP-0000000-53D7AE | RUSTSEC-2026-0145 |
| TEMP-0000000-54045E | more to CVE-2015-2059 |
| TEMP-0000000-556BB5 | tor TROVE-2023-006 |
| TEMP-0000000-561D64 | RUSTSEC-2022-0019 |
| TEMP-0000000-56C871 | Fixes permission check in QueriesController |
| TEMP-0000000-582CD7 | ruzstd uninit and out-of-bounds memory reads |
| TEMP-0000000-583651 | nspr, nss: unprotected environment variables |
| TEMP-0000000-58BE54 | lintian disclosure of file presense |
| TEMP-0000000-5A4286 | GHSA-wmpc-m6g9-fwj8: relay: Memory leak in API relay, endpoint "handshake" |
| TEMP-0000000-5AF47F | Remote DoS vulnerabilities in postgrey |
| TEMP-0000000-5C6A59 | session id exposed in portal AJAX responses |
| TEMP-0000000-5D7F62 | RUSTSEC-2025-0168 |
| TEMP-0000000-5DEDAF | RUSTSEC-2026-0112 |
| TEMP-0000000-5E8928 | sogo issues from 5.12.10 |
| TEMP-0000000-604AC4 | crashes on crafted upack packed file |
| TEMP-0000000-62CF51 | Buffer overflow in libotr |
| TEMP-0000000-62D57E | apt-cacher arbitrary command execution |
| TEMP-0000000-66FC9C | RUSTSEC-2024-0332: Degradation of service in h2 servers with CONTINUATION Flood |
| TEMP-0000000-673AE0 | ikiwiki allows web user to edit images and other non-page format files in the wiki |
| TEMP-0000000-6D001C | smb4k security issue |
| TEMP-0000000-6F5D6B | WSA-2026-6: xfer: Write of DCC file received outside of configured download path |
| TEMP-0000000-6F6CD4 | Insecure mailbox generation in passwd's useradd |
| TEMP-0000000-6FDF96 | TROVE-2026-034 |
| TEMP-0000000-70147B | Memory corruption |
| TEMP-0000000-70AB0A | gix-transport indirect code execution via malicious username |
| TEMP-0000000-711222 | RUSTSEC-2023-0057: Fails to prohibit standard library access prior to initialization of Rust standard library runtime |
| TEMP-0000000-71A9D4 | Unspecified buffer overflow in Convert::UUlib perl module |
| TEMP-0000000-72CE9B | WSA-2026-7: xfer: Buffer overflow when receiving a line in a Xfer chat (DCC chat) buffer |
| TEMP-0000000-72DB32 | RUSTSEC-2026-0222 |
| TEMP-0000000-73A1D3 | RUSTSEC-2023-0005 |
| TEMP-0000000-73CA4D | TROVE-2026-043 |
| TEMP-0000000-740209 | GHSA-pj8w-fh79-f438: rts_read_result length-checks 2 bytes and then reads 4 |
| TEMP-0000000-758242 | RUSTSEC-2022-0022 |
| TEMP-0000000-760107 | rtkit: failure to drop supplemental groups |
| TEMP-0000000-78A5AA | RUSTSEC-2026-0119 |
| TEMP-0000000-7C9547 | docker VMM breakout |
| TEMP-0000000-7CC552 | tor TROVE-2023-004 |
| TEMP-0000000-7D3048 | Logging bypassing through SIGHUP in syslog-ng |
| TEMP-0000000-7F4255 | RCE fixed in 4.4.23 |
| TEMP-0000000-803658 | several security fixes: PHP injections, XSS and secrets stored in session file |
| TEMP-0000000-80376F | integer overflow |
| TEMP-0000000-80BA67 | Rorster vulnerability similar to CVE-2015-8688 |
| TEMP-0000000-812972 | GHSA-4464-r7qj-pgrx: FreeRDP: server stores client Core Data DesktopWidth/Height unvalidated in GCC negotiation |
| TEMP-0000000-835FB2 | rust-atty: Potential unaligned read |
| TEMP-0000000-838979 | Escape href attribute in auto links |
| TEMP-0000000-84AA65 | DoS against clamav through infinite loop in cli_rmdirs |
| TEMP-0000000-87D161 | RUSTSEC-2026-0118 |
| TEMP-0000000-8B87A6 | mediawiki issues from 1.26.3, 1.25.6 and 1.23.14 |
| TEMP-0000000-8E2D4B | GHSA-23pf-q83q-x45r: Unbounded MonitorIds used as an array index in X11 monitor selection |
| TEMP-0000000-8F74CD | unsafe temporary file in lintian's objdump-info |
| TEMP-0000000-8FA4DB | GHSA-m85m-3qxv-63h5: Infinite loop / CPU DoS in pool_decode_rect |
| TEMP-0000000-905912 | Heap buffer overflow in unci mixed-interleave decoding with unequal chroma bit depths |
| TEMP-0000000-94515F | xile buffer overrun in terminal code |
| TEMP-0000000-964ED9 | AST-2016-005 |
| TEMP-0000000-96AFF4 | spip: Use a dedicated function to clean author data when preparing a session |
| TEMP-0000000-96B2E9 | hardening for RSA-CRT leak |
| TEMP-0000000-970209 | Invalid read in ensure_filepath |
| TEMP-0000000-9862C2 | RUSTSEC-2023-0078 |
| TEMP-0000000-9AC543 | mono xsp file disclosure |
| TEMP-0000000-9B1564 | tryton zipbomb DoS |
| TEMP-0000000-9B3182 | schroot may use outdated configuration information |
| TEMP-0000000-9BB4B1 | tryton-server lack of record validation |
| TEMP-0000000-9C2340 | GHSA-j5mq-3349-gwmm: channels,smartcard worker creation failure frees a devman-owned device |
| TEMP-0000000-9D9504 | tryton-server: Python code execution via uploaded templates |
| TEMP-0000000-A0AD39 | TROVE-2026-036 |
| TEMP-0000000-A2D002 | prelude-manager: password world-readable |
| TEMP-0000000-A2EB44 | Insecure tempfile in x-face-el |
| TEMP-0000000-A4EF31 | Null pointer access in inflatehd tool |
| TEMP-0000000-A4F3DE | Invalid read in create_output_name |
| TEMP-0000000-A510E8 | RUSTSEC-2026-0104 |
| TEMP-0000000-A5538F | libpam-ssh: Inproper caching of pwd data with potential security implications |
| TEMP-0000000-A6FE70 | TROVE-2026-040 |
| TEMP-0000000-A7B0B9 | RCE fixed in 4.4.22 |
| TEMP-0000000-A954ED | RUSTSEC-2026-0135 |
| TEMP-0000000-AA638E | SQL Injection in graph_templates.php |
| TEMP-0000000-AB5257 | dojo can be used as a redirector |
| TEMP-0000000-ACBC4C | buffer overflows in init_cups |
| TEMP-0000000-B138FB | gstreamer ffmpeg missing checks of packet sizes, chunk sizes, and fragment positions |
| TEMP-0000000-B1CD0A | WSA-2026-4: relay: Missing size limit for the received websocket frame, HTTP message and HTTP body |
| TEMP-0000000-B20F11 | RUSTSEC-2026-0234 |
| TEMP-0000000-B26F1D | WSA-2026-8: relay: Buffer overflow in dump of Relay data |
| TEMP-0000000-B2A20C | RUSTSEC-2024-0021 |
| TEMP-0000000-B32316 | TROVE-2026-004 |
| TEMP-0000000-B446CF | iodine: DoS against iodined triggerable by authenticated users |
| TEMP-0000000-B45CBC | RUSTSEC-2026-0223 |
| TEMP-0000000-B5A5F9 | RUSTSEC-2026-0136 |
| TEMP-0000000-B5C878 | backuppc: web frontend installed insecurely by default |
| TEMP-0000000-B96FAD | RUSTSEC-2025-0005: Out of bounds write triggered by crafted coverage data |
| TEMP-0000000-B9CD89 | BUG/MAJOR: http: prevent risk of reading past end with balance url_param |
| TEMP-0000000-BB5891 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and Double Free in libde265 |
| TEMP-0000000-BBB7D8 | remote memory disclosure |
| TEMP-0000000-BBBF43 | Crypto weakness in Tor's handshaking process |
| TEMP-0000000-BC4C2F | nautilus: file preview html script execution |
| TEMP-0000000-BCCC32 | vlc issues fixed in 3.0.13 |
| TEMP-0000000-BD209F | XSS via queue name in Sidekiq::Web |
| TEMP-0000000-BD3902 | sogo SOGoForbidUnknownDomainsAuth issue |
| TEMP-0000000-C04FE8 | dcerpc: exit()'s on malloc failure |
| TEMP-0000000-C0BE35 | RUSTSEC-2026-0183 |
| TEMP-0000000-C0C4D6 | GHSA-w9qg-g24r-77f6: URBDRC/libusb control-transfer path aborts on reachable OutputBufferSize assertion |
| TEMP-0000000-C0C622 | gstreamer-ffmpeg unspecified issue related to sps and pps ids |
| TEMP-0000000-C3CEDB | fscanf format string security bug in flashrom layout code |
| TEMP-0000000-C525DA | GHSA-x7v6-xfx3-52j6: FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS |
| TEMP-0000000-C6840A | RUSTSEC-2022-0020 |
| TEMP-0000000-C6AAE1 | Catch overflows in AVC/HEVC NAL unit length calculations |
| TEMP-0000000-C7DD3B | RUSTSEC-2024-0402 |
| TEMP-0000000-CD327C | remctl ACL bypass vulnerability |
| TEMP-0000000-CDF09E | TOCTOU race when expanding JAR files |
| TEMP-0000000-CE3B44 | XSA-166: ioreq handling possibly susceptible to multiple read issue |
| TEMP-0000000-CED930 | RUSTSEC-2024-0020 |
| TEMP-0000000-CF89FB | RUSTSEC-2026-0005: Potential use-after-free in oneshot when used asynchronously |
| TEMP-0000000-D02C9B | TROVE-2026-013 |
| TEMP-0000000-D22263 | Heap-buffer-overflow read in uncompressed (`uncv`) HEIF sequence RGB conversion for odd-height 4:2:0 frames |
| TEMP-0000000-D34B97 | RUSTSEC-2026-0134 |
| TEMP-0000000-D41D8C | |
| TEMP-0000000-D426B9 | TROVE-2026-014 |
| TEMP-0000000-D512DA | RUSTSEC-2026-0233 |
| TEMP-0000000-D61692 | unace unspecified security issue related to uninitialized variable |
| TEMP-0000000-D75F8B | RCE in gitlab-shell 2.6.6-2.6.7 |
| TEMP-0000000-D7B410 | RUSTSEC-2022-0021 |
| TEMP-0000000-D87CDB | validate a server certificate in a TLS-based server-server connection |
| TEMP-0000000-D8C3F4 | stack corruption when handling files with more than 64 audio channels |
| TEMP-0000000-D91305 | tcpdf code execution via tcpdf tag |
| TEMP-0000000-D99B95 | TROVE-2026-035 |
| TEMP-0000000-DAA254 | fai tempfile vulnerability |
| TEMP-0000000-DAE756 | clamav: DoS through multiple empty Content-Disposition header lines |
| TEMP-0000000-DD0D8E | RUSTSEC-2023-0015 |
| TEMP-0000000-DD73A0 | Unexpected database bindings via requests (follow-up) |
| TEMP-0000000-DD8D83 | crash during algorithmic detection on crafted PE file |
| TEMP-0000000-DEED53 | unrar: opens /tmp/debug_unrar.txt |
| TEMP-0000000-DF359B | GHSA-hg4r-vv53-vwf8: URBDRC out-of-bounds read in func_get_ep_desc via InterfaceNumber/array-position index mismatch |
| TEMP-0000000-E06059 | backup-manager: make sure password is not written to world-readable files |
| TEMP-0000000-E10713 | Multiple buffer overflows in gtetrinet |
| TEMP-0000000-E3BADF | RUSTSEC-2026-0013 |
| TEMP-0000000-E3DB33 | Several DoS possibilities of clients against the server in Freeciv |
| TEMP-0000000-E43D47 | SQL Injection in cdef.php |
| TEMP-0000000-E52D56 | Integer overflow in binutils' ELF parsing |
| TEMP-0000000-E57E4E | Remotely triggerable buffer overflow in OpenSMTPD |
| TEMP-0000000-E66AA0 | heap-use-after-free in decoder_context::reset() via dangling previous_slice_header |
| TEMP-0000000-E6792F | irssi missing null terminator |
| TEMP-0000000-E81ECD | RUSTSEC-2026-0113 |
| TEMP-0000000-E970CB | RUSTSEC-2026-0204 |
| TEMP-0000000-E9A545 | libetpan NULL deref |
| TEMP-0000000-EA2D06 | Endlees loop issue |
| TEMP-0000000-EC2CDF | RUSTSEC-2026-0235 |
| TEMP-0000000-ED74C7 | RUSTSEC-2023-0045 |
| TEMP-0000000-ED76D0 | Sanitizing and other XSS protections |
| TEMP-0000000-EF7B0A | RUSTSEC-2026-0184 |
| TEMP-0000000-EFA573 | SQL Injection Vulnerability in data sources |
| TEMP-0000000-F00632 | node-marked: multiple content injection vulnerabilities |
| TEMP-0000000-F090BB | directory traversal in servefile |
| TEMP-0000000-F1FB58 | WSA-2026-5: irc: Buffer overflow when receiving a DCC file |
| TEMP-0000000-F22D51 | SSLMate go-pkcs12: Authentication bypass in Decode functions |
| TEMP-0000000-F2843E | RUSTSEC-2026-0137 |
| TEMP-0000000-F32736 | SQL Injection Vulnerability in graph items and graph template items |
| TEMP-0000000-F41FA7 | DoS |
| TEMP-0000000-F43378 | GHSA-6mpx-c8rj-whj5: FreeRDP server DRDYNVC parser use-after-free during concurrent channel close |
| TEMP-0000000-F4C8D1 | ejabberd HTML code injection |
| TEMP-0000000-F565CB | RUSTSEC-2025-0167 |
| TEMP-0000000-F5DC1F | TROVE-2026-015 |
| TEMP-0000000-F6033C | SQL Injection in data_templates.php |
| TEMP-0000000-F707E4 | MATTA-2015-002: Enforce acceptable range for Diffie-Hellman server value |
| TEMP-0000000-F89685 | GHSA-r9pv-ffph-6gg6: Heap buffer overflow in nego_send_negotiation_request via oversized LB_LOAD_BALANCE_INFO routing token |
| TEMP-0000000-F971FC | TROVE-2025-015 |
| TEMP-0000000-F99584 | "slowloris" denial-of-service vulnerability in webservers |
| TEMP-0000000-F9A459 | XSS via job arguments display class in Sidekiq::Web |
| TEMP-0000000-FBC245 | GHSA-2vf2-grvj-6g8x: Heap buffer overflow in nego_send_negotiation_request |
| TEMP-0000000-FC713A | pythonpaste web root esacpe |
| TEMP-0000000-FD1F92 | root path disclosure |
| TEMP-0000000-FDAB26 | Transaction cache overrides the current user |
| TEMP-0046709-935F97 | Insecure access control on GNU Mach's IO ports |
| TEMP-0105562-0FE13B | crypt++ passes passwords through the command line |
| TEMP-0183047-CE70BA | fuzz: Insecure temp file usage |
| TEMP-0216566-EA84C5 | Insecure bounds checking in mpack's content parser |
| TEMP-0250106-DF1988 | Unspecified buffer overflow in libmng |
| TEMP-0253838-2AD268 | Minor local DoS as libldap |
| TEMP-0254101-876546 | Multiple buffer overflows in isoqlog |
| TEMP-0259987-89C19C | bash-completion: does not properly quote characters |
| TEMP-0269186-FFE79F | asciijump: /var/games/asciijump world writable |
| TEMP-0274229-6E02C2 | base-passwd: sets valid shells for system services |
| TEMP-0291452-29156B | gs-esp: Insecure usage of /tmp in source code |
| TEMP-0291613-A6DD69 | xshisen follows symlinks for shared gid games files |
| TEMP-0296112-517ED6 | libnet-ssleay-perl: /tmp/entropy insecure |
| TEMP-0298114-36C546 | nvi: init.d recover file security bugs |
| TEMP-0298929-838146 | Multiple security issues when using distcc without ssh auth |
| TEMP-0302454-1EA4A5 | trackballs: Follows symlinks as gid games |
| TEMP-0302790-27DC0A | hdup inproperly preserves permissions on directories |
| TEMP-0306076-4B7D89 | coreutils ignores umask when using -m in mkdir, mkfifo and mknod |
| TEMP-0308737-BABD6A | Heap overflow in libosip URI parsing |
| TEMP-0313081-3428D4 | DoS triggering endless loops in findutils -follow option |
| TEMP-0319686-D21D67 | xgalaga score file segfault |
| TEMP-0320150-40E143 | Integer overflow in ffmpeg's MPEG encoding |
| TEMP-0321447-C22A86 | Insecure usage of temporary files in x11perfcomp and other security issues |
| TEMP-0321470-3DB8C5 | wine: Unsafe use of temporary files in winelauncher |
| TEMP-0321566-40512D | fftw3-dev: Insecure tempfile usage in fftw-wisdom-to-conf script |
| TEMP-0325080-CF0752 | user password file created by gajim is world-readable |
| TEMP-0327261-B6AE8F | wine-safe does not prompt the user/is registered in mailcap |
| TEMP-0330627-887F38 | rkhunter: Insecure temporary file |
| TEMP-0331720-9168FE | adduser's deluser creates backup files with world readable permissions |
| TEMP-0334193-23D83A | xscreensaver does not maintain screen locks during upgrade |
| TEMP-0337492-CFA0CD | Insecure temp files in note |
| TEMP-0340079-E5FD8C | Insecure tempfile in libjpeg6b's exifautotran |
| TEMP-0340105-EE3BB8 | unsafe file permissions in vpnc |
| TEMP-0358139-D2A6EE | gauche-config rpath set to user home |
| TEMP-0358142-0BC2FF | unixodbc rpath set to /home |
| TEMP-0358157-34A070 | fftw rpath set to user home |
| TEMP-0358166-12F63F | hamlib3-perl rpath set to user home |
| TEMP-0359745-ECBE05 | webalizer: symlink vulnerability |
| TEMP-0361653-A94AFD | librsvg2 crash on certain svg files |
| TEMP-0361913-F8E45A | linphone insecure password leakage |
| TEMP-0368804-259562 | ldap account manager sets trivial password instead of disabling it |
| TEMP-0369014-6AE03E | 'Cache' shell injection vulnerability |
| TEMP-0369542-32FFCA | ssmtp password leak |
| TEMP-0370144-2CA0D8 | specialy crafted WAV turns mkvmerge into a malloc bomb |
| TEMP-0375453-4F9189 | ldap account manager wrongly unlocks some passwords |
| TEMP-0378571-06BD02 | courier-authdaemon: wrong socket permissions may lead to password disclosure |
| TEMP-0379922-FA0DE2 | double-free vulnerability in the Real Media demuxer |
| TEMP-0382132-C0E39C | diffmon information leakage |
| TEMP-0388608-F17697 | logrotate race condition could lead to file disclosure |
| TEMP-0391388-8371AD | zabbix buffer overflows |
| TEMP-0391388-A7E978 | zabbix format string vulnerabilities |
| TEMP-0393846-B78E90 | motion insecure tempfile creation |
| TEMP-0397297-E6F2D0 | obexpushd arbitrary command execution |
| TEMP-0399226-A0B8DF | yacas insecure rpath |
| TEMP-0400624-86BB88 | dsniff urlsnarf missing output sanitization |
| TEMP-0403141-57B365 | znc file access security hole |
| TEMP-0407003-DA457C | various crashes and infinite loops in ffmpeg |
| TEMP-0407116-23D9EF | wordpress unregister_globals workaround from 2.0.7 |
| TEMP-0407605-7D944E | netpbm heap corruption |
| TEMP-0407607-240F77 | python-django flup/FastCGI/debugging issue |
| TEMP-0410557-009D67 | dokuwiki conf directory accessible by web users |
| TEMP-0410588-2CACBB | amavids-new uses contrib/non-free packers without security support in default config |
| TEMP-0412618-38583E | apg generates insecure passwords on 64-bit architectures |
| TEMP-0417995-6A1CD7 | initramfs-tools creates /dev/root world-readable |
| TEMP-0425254-0F9CE1 | insecure tempfile in wdiff |
| TEMP-0427715-C31B61 | webpy HTTP response splitting vulnerability |
| TEMP-0434134-B27890 | dokuwiki XSS in spellchecker |
| TEMP-0454297-EACDD7 | exempi buffer overflow in GIF ReadHeader() function |
| TEMP-0464084-305C70 | greylistd bypass |
| TEMP-0464778-7EAAA3 | tdiary XSS |
| TEMP-0465561-A017B1 | minor cyrus sasl DoS |
| TEMP-0482385-09F6D5 | resizing the monitor with xrandr can crash xscreensaver |
| TEMP-0484639-8D3138 | missing sanity checks allow DoS via mis-formated timestamp |
| TEMP-0496462-B3176F | insecure temp file in nvi |
| TEMP-0497005-8CD734 | Overwrite certain images without notice |
| TEMP-0497005-A51CB0 | Overwrite symlink without check |
| TEMP-0497452-F45308 | nfdump vulnerable to symlink attacks |
| TEMP-0500295-A176F7 | possible script injection via /etc/wordpress/wp-config.php |
| TEMP-0500611-22A0F0 | jumpnbump: insecure temp file |
| TEMP-0506961-3C07AF | auctex insecure temp file |
| TEMP-0507482-9415A7 | Insecure tmpdir creation |
| TEMP-0508111-173336 | Insecure tempfile creation |
| TEMP-0514151-B17364 | samba: Account locking out doesnt work with an LDAP backend |
| TEMP-0515104-609AB4 | nautilus: potential exploits via application launchers |
| TEMP-0523476-4CE9EF | pptp-linux: unrestrictive pptpsetup permissions |
| TEMP-0525820-07BBE3 | More file buffer overflows |
| TEMP-0528434-FDFF92 | cron: Incomplete fix for CVE-2006-2607 (setgid() and initgroups() not checked |
| TEMP-0531735-61C2C9 | OCS Inventory NG SQL Injection Vulnerability |
| TEMP-0532514-9137E0 | predictable random number generator used in web browsers |
| TEMP-0532740-DB1B64 | libdkim: signature parsing is not thread-safe |
| TEMP-0533670-BB9FF7 | pcsc-lite: creates world-writable directory |
| TEMP-0535159-76AB98 | ser2net DoS |
| TEMP-0535881-957F77 | clamav scanner bypass with archives |
| TEMP-0535886-8B62DC | apache2: htaccess override |
| TEMP-0535946-7636B8 | libio-socket-ssl-perl: partial hostname matching vulnerability |
| TEMP-0539699-BC7A2B | xscreensaver: local screen lock bypassable via low resolution video devices |
| TEMP-0548909-2413C6 | xen-tools: world readable disk image files |
| TEMP-0551907-963784 | mandos 0600 file being included in initrd |
| TEMP-0552518-ADA4BA | eglibc: ldd arbitrary code execution |
| TEMP-0555308-79E91C | xserver-xorg: inherits user's mask |
| TEMP-0560087-F084E6 | xpat2: save game permissions issue |
| TEMP-0560895-39B4B0 | gnome-screensaver inhibitor not removed when connection is closed |
| TEMP-0566326-9A899F | sqlite: info leak |
| TEMP-0567175-3A30A9 | gmetad incorrect file permissions |
| TEMP-0568925-CB8E83 | esmtp: world-readable config file |
| TEMP-0570713-FED4BB | ffmpeg potentially remaining vulnerabilities after DSA 2000 |
| TEMP-0579087-7F12A8 | prosody password world-readable |
| TEMP-0592115-F98F5C | signature verification issue |
| TEMP-0593829-E6A4BC | config file world readable |
| TEMP-0597382-058DA8 | mingetty directory traversal |
| TEMP-0601325-4C9A5B | insecure handling of /tmp files in debian/preinst |
| TEMP-0601525-BEBB65 | libgd2: gdImageColorTransparent can write outside buffer |
| TEMP-0601585-D41D8C | |
| TEMP-0605160-28DAD2 | insecure python path handling |
| TEMP-0607494-376E2E | XSS in ftpls |
| TEMP-0608822-E0260C | calibre XSS |
| TEMP-0608822-EF2F16 | calibre file disclosure |
| TEMP-0608979-E8B8DF | Crash with long HOME environment variable |
| TEMP-0609212-CA8607 | multiple spip issues |
| TEMP-0612034-33CBAD | aptitude tempfile |
| TEMP-0612668-CE1EF5 | evince segfault |
| TEMP-0632260-7A1354 | stardict: minor information disclosure |
| TEMP-0635836-4F6C5C | minissdpd multiple issues |
| TEMP-0646758-12F1BD | spip path disclosure |
| TEMP-0649113-5F7BC7 | spip privilege escalation |
| TEMP-0649113-869F0D | spip XSS |
| TEMP-0672435-7C494C | Option -localhost seems to fail to restrict ipv6 access |
| TEMP-0672961-92221C | two XSS |
| TEMP-0678189-8A5546 | packagekit insecure temp file |
| TEMP-0678512-2E167C | remotely triggerable crash |
| TEMP-0682869-4EFB12 | insecure default configuration / authentication bypass |
| TEMP-0683667-E2E855 | base name disclosure |
| TEMP-0684143-02E960 | redeclipse code execution through map files |
| TEMP-0698189-BE9FC4 | buffer overflow in commandline parsing |
| TEMP-0706095-6DFA71 | autopostgresqlbackup code injection |
| TEMP-0706099-FAF305 | automysqlbackup code injection |
| TEMP-0729276-2DADFA | staden-io-lib buffer overflow |
| TEMP-0740268-4CE61C | buffer overflow |
| TEMP-0745580-D90EF4 | Insecure default permissions for ~/.virtualenvs and scripts |
| TEMP-0764645-2E1644 | iptables-persistent minor local info leak |
| TEMP-0764814-3B6657 | freecad downloads and executes code |
| TEMP-0769606-4AA6CF | a2p: buffer overflow |
| TEMP-0769937-FD49EE | formail: memory corruption |
| TEMP-0770647-53FAC2 | libclamunrar: double-free error libclamunrar_iface/unrar_iface.c |
| TEMP-0773308-EE1012 | crashes on crafted ELF |
| TEMP-0773751-AD275E | race condition between fur and fex_cleanup may create internal instead of external user |
| TEMP-0774171-B2A845 | symlink directory traversal |
| TEMP-0774555-E962AD | insecure LUA default load path |
| TEMP-0774769-57BAAA | saves unknown host's fingerprint in known_hosts without any prompt |
| TEMP-0774897-BC9A31 | denial of service with specific packets |
| TEMP-0774898-681A65 | fails to detect silent driver failure to change MAC |
| TEMP-0775193-7F000E | djvudigital: insecure use of /tmp |
| TEMP-0775199-D05A9E | smime_keys: insecure use of /tmp |
| TEMP-0775479-AC2272 | insecure configuration permissions |
| TEMP-0775662-9BBEA1 | Insufficient validation of USB device descriptors |
| TEMP-0776271-06C3A9 | Infinite loop in patch |
| TEMP-0777522-650525 | denial of service under memory stress |
| TEMP-0777706-EB0F2E | insecure storage of password in the NUT-monitor app |
| TEMP-0778511-AAAFE7 | more to CVE-2014-6585 |
| TEMP-0779573-6C7D15 | heap buffer overflow |
| TEMP-0780100-E2856F | tcllib XSS |
| TEMP-0780178-BE09AB | several security vulnerabilities and network packets can terminate the connection |
| TEMP-0780503-1359A5 | Incomplete fix for CVE-2014-7940 |
| TEMP-0780712-D0DD02 | permissive file access allowed from nasal |
| TEMP-0780716-B04986 | nasal scripts can ready any file |
| TEMP-0780817-7C5137 | Insufficient escaping in user manager allows XSS attack |
| TEMP-0781608-198474 | caja automounts USB flash drives and CD/DVD drives while session is locked |
| TEMP-0781640-F16931 | Signature Bypass in several JSON Web Token Libraries |
| TEMP-0783007-4C0B51 | http uri parsing issue |
| TEMP-0783347-555527 | files with invalid or unsafe names could be uploaded |
| TEMP-0783347-AEABE2 | Some plugins were vulnerable to an SQL injection vulnerability |
| TEMP-0784712-056A32 | incorrect parsing of from header when assigning pgp keys |
| TEMP-0784712-E83200 | incorrect substring matching when assigning pgp keys |
| TEMP-0784889-495CCA | pdf2djvu: insecure use of /tmp when executing c44 |
| TEMP-0785364-25992B | XSS in group administration |
| TEMP-0786423-948688 | rsync collision attack |
| TEMP-0786804-C23D2B | hwclock(8) SUID privilege escalation |
| TEMP-0795062-DA89AB | publicfile-installer: insecure use of /tmp |
| TEMP-0805638-5AC56F | Insecure permissions for backup directory |
| TEMP-0805657-81BB13 | Missing bounds checking and verification of data type causes segfault |
| TEMP-0807341-84E914 | uses non-random tempdir /tmp/tmprepo.0/.git/ |
| TEMP-0811308-B63DA1 | Multiple minor security issues |
| TEMP-0816034-9C45DC | unsafe use of /tmp |
| TEMP-0820594-BC6826 | out of bound read and write issues |
| TEMP-0825151-E80EFA | CSRF protection for POST requests |
| TEMP-0827346-22ED59 | install-sh: insecure use of /tmp |
| TEMP-0827564-93E4E3 | Stack corruption from crafted pattern |
| TEMP-0830660-09AE85 | Insecure use of /tmp |
| TEMP-0832169-0F9220 | insecure default PATH |
| TEMP-0841257-B7CD60 | sendmail: Privilege escalation from group smmsp to root |
| TEMP-0846838-9738BD | tiffcrop: divide-by-zero in readSeparateStripsIntoBuffer when BitsPerSample is missing |
| TEMP-0850432-8BD66F | multiple new security issues |
| TEMP-0853951-A77B7B | iio-sensor-proxy: insecure dbus policy |
| TEMP-0855108-573218 | irssi memory leak |
| TEMP-0856196-13C562 | scanelf: out of bounds read in scanelf_file_get_symtabs (scanelf.c) |
| TEMP-0856648-2BC2C9 | dns: out of bound memory read |
| TEMP-0857546-8B0EB6 | Server certificates are not verified |
| TEMP-0860565-9E8C4B | XSA-206: xenstore denial of service via repeated update |
| TEMP-0868134-294030 | out-of-bounds read in eexec_line() |
| TEMP-0869722-31618B | memory leak in quantize |
| TEMP-0870233-1DD19E | executes javascript code downloaded from insecure URL |
| TEMP-0876540-D98160 | pcb code injection by malicious layout file |
| TEMP-0904191-9063D5 | Incomplete fix for CVE-2018-10886 |
| TEMP-0905332-CB57BF | Default KeyInfo resolver doesn't check for empty element content. |
| TEMP-0913136-041770 | DSA verification crashes OpenSSL on invalid combinations of key content |
| TEMP-0913137-22A98C | VirtualBox E1000 Guest-to-Host Escape |
| TEMP-0921565-C5FF8E | netmask: buffer overflow vulnerability |
| TEMP-0922080-E6D428 | fuse mount exposes backup to unauthorized users |
| TEMP-0923926-B85BA9 | high memory usage with some long running sessions |
| TEMP-0925959-45DD25 | insecure handling of /tmp/VMwareDnD |
| TEMP-0930387-988530 | security issues fixed in 1.8.5 |
| TEMP-0950121-6A81FC | opensmtpd DoS via opportunistic TLS downgrade |
| TEMP-0950816-47D88A | mpv insecure lua loadpath |
| TEMP-0964568-93C065 | veyon-configurator tmp handling |
| TEMP-0987831-866E01 | SQL Server LIMIT / OFFSET SQL Injection |
| TEMP-0993866-37A39B | jwe cbc tag computation error |
| TEMP-0993866-50C165 | jws alg:none signature verification issue |
| TEMP-0995562-06835D | RUSTSEC-2021-0119: Out-of-bounds write in nix::unistd::getgrouplist |
| TEMP-0996913-660A41 | RUSTSEC-2020-0159: Potential segfault in localtime_r invocations |
| TEMP-1007145-ABA7D9 | wordpress 5.9.2 |
| TEMP-1022575-434581 | wordpress 6.0.3 |
| TEMP-1027282-04F215 | RUSTSEC-2022-0074 |
| TEMP-1031542-93CC2D | XSS Vulnerability in matrix.pl |
| TEMP-1032088-3E13DF | RUSTSEC-2022-0078 |
| TEMP-1034374-6E2515 | https://rustsec.org/advisories/RUSTSEC-2023-0031.html |
| TEMP-1036689-1CA7FB | Block themes parsing shortcodes in user-generated data |
| TEMP-1050298-39CD6D | RUSTSEC-2023-0053: rustls-webpki: CPU denial of service in certificate path building |
| TEMP-1050299-7F4591 | RUSTSEC-2023-0052 webpki: CPU denial of service in certificate path building |
| TEMP-1052200-1C589C | receiving with Lightning: partial MPP might be accepted |
| TEMP-1053115-9454E3 | code execution via malformed XTGETTCAP |
| TEMP-1055895-2C681F | RUSTSEC-2023-0070: Insufficient covariance check makes self_cell unsound |
| TEMP-1059234-46A2BA | RUSTSEC-2023-0075 |
| TEMP-1079517-4BBE9B | RUSTSEC-2024-0363: Binary Protocol Misinterpretation caused by Truncat ... |
| TEMP-1082053-F368BB | RUSTSEC-2023-0086 |
| TEMP-1091632-3774D9 | RUSTSEC-2024-0428 |
| TEMP-1103894-9182BD | RUSTSEC-2025-0020 |
| TEMP-1103988-584961 | RUSTSEC-2025-0023 |
| TEMP-1104554-71A417 | Integer overflow with decimal numbers in calculation of expression |
| TEMP-1104554-9D6627 | Buffer overflow in syntax highlighting of evaluated expressions |
| TEMP-1104554-A4A19A | Buffer overflow in parsing of date/time |
| TEMP-1104554-B16504 | Integer overflow in base32 decode/encode functions |
| TEMP-1104554-D19F68 | Buffer overflow in range of chars in evaluated expressions |
| TEMP-1104554-D6608C | Integer overflow in conversion of version to an integer |
| TEMP-1104554-F3166C | Buffer overflow in base 32 encoding in evaluated expressions |
| TEMP-1111689-27EE99 | OSSN-0094 |
| TEMP-1111844-CF9125 | qemu: stop using C (Credentials) flag for binfmt_misc registration |
| TEMP-1112471-76797E | RUSTSEC-2025-0051 |
| TEMP-1115977-4FD111 | RUSTSEC-2025-0071 |
| TEMP-1124688-97C512 | RUSTSEC-2026-0001 |
| TEMP-1127315-BE4F15 | RUSTSEC-2026-0008 |
| TEMP-1132945-4CEFB2 | GHSA-89xm-3m96-w3jg: cross-user CancelPull orphans another user's ongoing pull |
| TEMP-1132946-5EDD2C | GHSA-2fxp-43j9-pwvc: Arbitrary read-access to files readable by _flatpak user |
| TEMP-1133085-EC036F | RUSTSEC-2026-0049 |
| TEMP-1134947-DEEDE9 | RUSTSEC-2026-0111 |
| TEMP-1136340-4D3952 | CSRF Security Fix |
| TEMP-1138794-BADE22 | HTTP/2 Bomb denial of service |
| TEMP-1138849-FDBA9E | Mistral workflow execution context exposes Keystone auth token |
| TEMP-1139004-33118B | heap out-of-bounds write in fax backend on zero-length input |
| TEMP-1139005-4885B2 | heap out-of-bounds read in fax backend FAXMAGIC comparison |
| TEMP-1139007-21322A | heap out-of-bounds read in fax backend Ghostscript header handling |
| TEMP-1139008-F7B58F | unsigned integer wrap-around in fax backend leads to heap out-of-bounds read and write |
| TEMP-1139009-9CE18E | integer overflow in fax image allocation leads to undersized heap allocation |
| TEMP-1139876-2010E8 | RUSTSEC-2026-0180 |
| TEMP-1139876-F3C684 | RUSTSEC-2026-0179 |
| TEMP-1139877-7225AC | RUSTSEC-2026-0172 |
| TEMP-1140011-71A42A | RUSTSEC-2026-0176 |
| TEMP-1140013-2F2A60 | RUSTSEC-2026-0178 |
| TEMP-1140176-50C86A | default policy.xml HTTP/HTTPS/URL delegate rules are no-ops |
| TEMP-1141479-B41609 | RUSTSEC-2026-0186 |
| TEMP-1142113-1BFB50 | Nova console WebSocket proxy Origin allow-list poisoning |
| TEMP-1142597-FFA22A | GHSA-68ff-gq39-pqjm: relay: authentication bypass with the "plain" password hash algorithm |
| TEMP-1142894-2C375F | GHSA-q2xg-9ggx-77mr: Stack buffer overflow in irc_message_split_join when building a JOIN with keys |
| TEMP-1142894-B589E0 | GHSA-hx59-4hq9-6vmw: relay: use-after-free and double free when a remote relay sends an event with an array as body |
| TEMP-1142894-D4016A | GHSA-rfmh-3r7f-jpx5: Use-after-free in the irc plugin when a batched message disconnects the server |
| TEMP-1142904-117334 | heap OOB read in EF_IZUNIX3 extra field handler |
| TEMP-1142905-081994 | stack out-of-bounds NUL write in EF_SMARTZIP handler |
| TEMP-1142906-2C6C79 | heap buffer overflow WRITE in memextract() STORED path |
| TEMP-1142937-657D95 | Neutron sub-resource APIs do not verify parent ownership |
| TEMP-1143114-235E9E | RUSTSEC-2024-0429 |
| TEMP-1143804-40DE70 | OSSN-0103 |
| TEMP-1143866-6DBA82 | Command injection issue with zip |
| TEMP-1144105-8C4D6A | GHSA-7cgc-gp99-6jmm: resource exhaustion via LZMA decoding |
| TEMP-1144106-D6004A | GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems |
| TEMP-1144129-D6CF99 | GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses path/interface/member checks |
| TEMP-1144130-0EF88B | GHSA-v2gw-v9h5-9q4x |
| TEMP-1144130-40A79A | GHSA-8qxj-x646-phcm |
| TEMP-1144130-44EC0B | GHSA-qrwq-7qwx-q9rp |
| TEMP-1144130-71598F | GHSA-w69g-9x8j-7p8f |
| TEMP-1144130-80BBC5 | GHSA-fqx6-vh4p-42cg |
| TEMP-1144130-973A49 | GHSA-jr92-2v97-wgvc |
| TEMP-1144130-B3D5FC | GHSA-q4gr-vc25-57m5 |
| TEMP-1144130-BEF59A | GHSA-9rww-v4mm-x4jg |
| TEMP-1144130-FF3646 | GHSA-99wv-m8rp-g58x |
| TEMP-1144214-4C9607 | OSSN-0106: API ramdisk endpoints require network-level access controls |
| TEMP-1144395-348CC4 | RUSTSEC-2026-0221 |
| TEMP-1144640-5ABA9D | divide-by-zero on zero glyph width causes crash |
| TEMP-1144641-391451 | out-of-bounds read through attacker-controlled property offset |
| TEMP-1144642-D02975 | out-of-bounds read in szLpstr/xstrdup may expose adjacent heap data |
| TEMP-1144643-BC29B7 | heap out-of-bounds write when appending font-table entry |
| TEMP-1144645-69C016 | heap out-of-bounds write during Unicode font-name conversion |
| TEMP-1144839-91D17B | GHSA-xrfq-jhgh-wqch: Authentication bypass in the web interface |
| TEMP-1145563-076BF6 | GHSA-rgqj-28c2-gxwp: Unauthenticated API mode confusion allows configuration takeover and remote code execution |
| TEMP-1145563-F10EE7 | GHSA-75g3-96fr-7p2r: SABnzbd PAR2 path traversal enabling cross-job __verified__ pickle RCE |
| TEMP-1146838-05CD08 | `is_local_url()` bypass via trailing-dot FQDN in stylesheet URL |
| TEMP-1146838-17D26D | Zero-click stored XSS via TNEF MIME tag injection in the attachment URL |
| TEMP-1146838-184AD1 | Cross-user access in contact group membership (add/remove) in the SQL address book |
| TEMP-1146838-192392 | Remote-content blocker bypass via SVG SMIL src animation |
| TEMP-1146838-1D84E4 | XSS in the HTML editor using text/enriched part content |
| TEMP-1146838-252E75 | CSS declaration smuggling via un-encoded ampersand emission |
| TEMP-1146838-2C017C | Email header injection via identity's organization field |
| TEMP-1146838-2D86BF | CSS property injection via body `background` attribute |
| TEMP-1146838-61F931 | Remote content blocking bypass via CSS escapes in FuncIRI attributes |
| TEMP-1146838-6627BB | SSRF bypass in Roundcube CSS proxy via hexadecimal IPv6-mapped IPv4 addresses |
| TEMP-1146838-752355 | Email header injection via bare CR in the subject field |
| TEMP-1146838-FA492B | Email header injection via C-escape \r in the recipient display name |
| TEMP-1147154-EA5624 | GHSA-q326-jpxx-jmjc: __wrapped__ dispatch bypass allows unauthenticated API access |
| TEMP-1147154-ECE4C7 | GHSA-mjwj-v5mr-cmcg: PAR2 symlink bypass allows pickle remote code execution. |
| TEMP-1147318-639065 | GHSA-5qpq-xqfv-j9pg: Invalid write if a decoder is reinitialized after allocation failure |