Vulnerabilities (CVE)

Total 396933 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-0860 2 Canonical, Debian 2 Ubuntu Linux, Dpkg 2026-06-17 7.5 HIGH N/A
Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1.17.26 allows remote attackers to execute arbitrary code via the archive magic version number in an "old-style" Debian binary package, which triggers a stack-based buffer overflow.
CVE-2015-0859 1 Debian 1 Debian Linux 2026-06-17 7.5 HIGH N/A
The Debian build procedure for the smokeping package in wheezy before 2.6.8-2+deb7u1 and jessie before 2.6.9-1+deb8u1 does not properly configure the way Apache httpd passes arguments to smokeping_cgi, which allows remote attackers to execute arbitrary code via crafted CGI arguments.
CVE-2015-0858 2 Debian, Tardiff Project 2 Debian Linux, Tardiff 2026-06-17 2.1 LOW 3.3 LOW
Cool Projects TarDiff allows local users to write to arbitrary files via a symlink attack on a pathname in a /tmp/tardiff-$$ temporary directory.
CVE-2015-0857 2 Debian, Tardiff Project 2 Debian Linux, Tardiff 2026-06-17 10.0 HIGH 9.8 CRITICAL
Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file.
CVE-2015-0856 2 Fedoraproject, Sddm Project 2 Fedora, Sddm 2026-06-17 4.6 MEDIUM N/A
daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.
CVE-2015-0855 1 Pitivi 1 Pitivi 2026-06-17 10.0 HIGH 9.8 CRITICAL
The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file path.
CVE-2015-0854 1 Shutter-project 1 Shutter 2026-06-17 9.3 HIGH 7.8 HIGH
App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action.
CVE-2015-0853 1 Pysvn Project 1 Svn-workbench 2026-06-17 9.3 HIGH 8.8 HIGH
svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by using the "Command Shell" menu item while in the directory trunk/$(xeyes).
CVE-2015-0852 1 Freeimage Project 1 Freeimage 2026-06-17 5.0 MEDIUM N/A
Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corruption) via vectors related to the height and width of a window.
CVE-2015-0851 1 Xmltooling Project 1 Xmltooling 2026-06-17 5.0 MEDIUM N/A
XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cause a denial of service (crash) via schema-invalid XML data.
CVE-2015-0850 1 Fusionforge 1 Fusionforge 2026-06-17 10.0 HIGH N/A
The Git plugin for FusionForge before 6.0rc4 allows remote attackers to execute arbitrary code via an unspecified parameter when creating a secondary Git repository.
CVE-2015-0849 1 Debian 1 Pycode-browser 2026-06-17 N/A 3.9 LOW
pycode-browser before version 1.0 is prone to a predictable temporary file vulnerability.
CVE-2015-0848 3 Fedoraproject, Opensuse, Wvware 3 Fedora, Opensuse, Libwmf 2026-06-17 6.8 MEDIUM N/A
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
CVE-2015-0847 2 Canonical, Wouter Verhelst 2 Ubuntu Linux, Nbd 2026-06-17 7.8 HIGH N/A
nbd-server.c in Network Block Device (nbd-server) before 3.11 does not properly handle signals, which allows remote attackers to cause a denial of service (deadlock) via unspecified vectors.
CVE-2015-0846 1 Django-markupfield Project 1 Django-markupfield 2026-06-17 5.0 MEDIUM N/A
django-markupfield before 1.3.2 uses the default docutils RESTRUCTUREDTEXT_FILTER_SETTINGS settings, which allows remote attackers to include and read arbitrary files via unspecified vectors.
CVE-2015-0845 1 Sixapart 1 Movabletype 2026-06-17 7.5 HIGH N/A
Format string vulnerability in Movable Type Pro, Open Source, and Advanced before 5.2.13 and Pro and Advanced 6.0.x before 6.0.8 allows remote attackers to execute arbitrary code via vectors related to localization of templates.
CVE-2015-0844 2 Fedoraproject, Wesnoth 2 Fedora, Battle For Wesnoth 2026-06-17 5.0 MEDIUM N/A
The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1) campaign or (2) map file.
CVE-2015-0843 1 Debian 1 Yubiserver 2026-06-17 N/A 9.8 CRITICAL
yubiserver before 0.6 is prone to buffer overflows due to misuse of sprintf.
CVE-2015-0842 1 Debian 1 Yubiserver 2026-06-17 N/A 9.8 CRITICAL
yubiserver before 0.6 is prone to SQL injection issues, potentially leading to an authentication bypass.
CVE-2015-0841 1 Monopd Project 1 Monopd 2026-06-17 5.0 MEDIUM 7.5 HIGH
Off-by-one error in the readBuf function in listener.cpp in libcapsinetwork and monopd before 0.9.8, allows remote attackers to cause a denial of service (crash) via a long line.