NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
29381  CVE-2014-0488  APT before 1.0.9 does not "invalidate repository data" when moving from an unauthenticated to authenticated state, which allows remote attackers to have unspecified impact via crafted repository data.    6.8  Medium  2017-01-19  2014-11-04  View
29372  CVE-2014-0478  APT before 1.0.4 does not properly validate source packages, which allows man-in-the-middle attackers to download and install Trojan horse packages by removing the Release signature.    Medium  2017-01-19  2014-06-26  View
8710  CVE-2011-1829  APT before 0.8.15.2 does not properly validate inline GPG signatures, which allows man-in-the-middle attackers to install modified packages via vectors involving lack of an initial clearsigned message.    4.3  Medium  2017-01-07  2011-08-01  View
43006  CVE-2012-0961  Apt 0.8.16~exp5ubuntu13.x before 0.8.16~exp5ubuntu13.6, 0.8.16~exp12ubuntu10.x before 0.8.16~exp12ubuntu10.7, and 0.9.7.5ubuntu5.x before 0.9.7.5ubuntu5.2, as used in Ubuntu, uses world-readable permissions for /var/log/apt/term.log, which allows local users to obtain sensitive shell information by reading the log file.    2.1  Low  2017-01-19  2012-12-31  View
37317  CVE-2013-1051  apt 0.8.16, 0.9.7, and possibly other versions does not properly handle InRelease files, which allows man-in-the-middle attackers to modify packages before installation via unknown vectors, possibly related to integrity checking and the use of third-party repositories.    4.3  Medium  2017-01-18  2013-03-22  View

Page 16308 of 17672, showing 5 records out of 88360 total, starting on record 81536, ending on 81540

Actions