Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
debian debian linux 4.0 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2009-0255
The System extension Install tool in TYPO3 4.0.0 up to and including 4.0.9, 4.1.0 up to and including 4.1.7, and 4.2.0 up to and including 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for malicious users to crack the key.
Typo3 Typo3
Debian Debian Linux 4.0
NA
CVE-2008-4359
lighttpd prior to 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote malicious users to bypass intended access restrictions, and obtain sensitive information or possibly modi...
Lighttpd Lighttpd
Debian Debian Linux 4.0
NA
CVE-2008-4360
mod_userdir in lighttpd prior to 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote malicious users to bypass intended access restrictions, as demons...
Lighttpd Lighttpd
Debian Debian Linux 4.0
NA
CVE-2008-3912
libclamav in ClamAV prior to 0.94 allows malicious users to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.
Clamav Clamav
Debian Debian Linux 4.0
NA
CVE-2008-3913
Multiple memory leaks in freshclam/manager.c in ClamAV prior to 0.94 might allow malicious users to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".
Clamav Clamav
Debian Debian Linux 4.0
NA
CVE-2008-3325
Cross-site request forgery (CSRF) vulnerability in Moodle 1.6.x prior to 1.6.7 and 1.7.x prior to 1.7.5 allows remote malicious users to modify profile settings and gain privileges as other users via a link or IMG tag to the user edit profile page.
Moodle Moodle
Debian Debian Linux 4.0
NA
CVE-2008-1531
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and previous versions, and 1.5.x prior to 1.5.0, allows remote malicious users to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download ha...
Lighttpd Lighttpd
Debian Debian Linux 4.0
5.5
CVSSv3
CVE-2008-4302
fs/splice.c in the splice subsystem in the Linux kernel prior to 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of service (kernel BUG an...
Linux Linux Kernel
Debian Debian Linux 4.0
Redhat Enterprise Linux 5.0
1 EDB exploit
NA
CVE-2009-4017
PHP prior to 5.2.12 and 5.3.x prior to 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote malicious users to cause a denial of service (resource exhaustion), and makes it easier for remote malicious ...
Php Php
Php Php 5.3.0
Debian Debian Linux 5.0
Apple Mac Os X 10.6.3
Debian Debian Linux 4.0
Debian Debian Linux 6.0
1 EDB exploit
7.5
CVSSv3
CVE-2007-3409
Net::DNS prior to 0.60, a Perl module, allows remote malicious users to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop.
Net-dns Net
Debian Debian Linux 3.1
Debian Debian Linux 4.0
Canonical Ubuntu Linux 6.10
Canonical Ubuntu Linux 6.06
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23692
malicious code
XML injection
CVE-2024-28020
CVE-2024-35252
CVE-2024-5833
CVE-2024-30066
injection
CVE-2024-23282
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »