Todo Lists - Arch Linux Security Tracker


Scheduled advisories

Advisory Group Package Severity Type
ASA-201701-38 AVG-151 linux-zen Medium privilege escalation
ASA-201701-37 AVG-154 openssl Medium multiple issues

Undetermined groups

Group Package Severity Affected Status
AVG-128 firejail High 0.9.44.2-1 Unknown

Issues missing details

Issue Severity Remote Type Description
CVE-2016-9591 High Unknown Arbitrary code execution
a heap-use-after-free vulnerability has been found in  jasper. The vulnerability exists in...
CVE-2016-10123 Unknown Unknown Unknown
CVE-2016-10122 Unknown Unknown Unknown
CVE-2016-10121 Unknown Unknown Unknown
CVE-2016-10120 Unknown Unknown Unknown
CVE-2016-10119 Unknown Unknown Unknown
CVE-2016-10118 Unknown Unknown Unknown
CVE-2016-10117 Unknown Unknown Unknown

Orphan issues

Issue Severity Remote Type Description
CVE-2016-1000000 High Yes Sql injection
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection
CVE-2016-1951 Medium Yes Arbitrary code execution
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before...
CVE-2016-5258 Critical Yes Arbitrary code execution
Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and...
CVE-2016-7053 Medium Yes Denial of service
Applications parsing invalid CMS structures can crash with a NULL pointer dereference. This...
CVE-2016-9427 High Yes Arbitrary code execution
An integer overflow problem has been discovered leading to hep corruption. When calling...
CVE-2016-9443 High Yes Arbitrary code execution
Null pointer dereference in formUpdateBuffer
CVE-2017-5375 Critical Yes Arbitrary code execution
JIT code allocation in Firefox < 51 and Thunderbird < 45.7 can allow for a bypass of ASLR...
CVE-2017-5376 Critical Yes Arbitrary code execution
A use-after-free vulnerability has been found in Firefox < 51 and Thunderbird < 45.7, while...
CVE-2017-5377 Critical Yes Arbitrary code execution
A memory corruption vulnerability in Skia that can occur when using transforms to make...
CVE-2017-5378 High Yes Information disclosure
An information disclosure vulnerability has been found in Firefox < 51 and Thunderbird <...
CVE-2017-5379 High Yes Arbitrary code execution
A use-after-free vulnerability has been found in Firefox < 5,  in Web Animations, when...
CVE-2017-5380 High Yes Arbitrary code execution
A potential use-after-free vulnerability during DOM manipulation of SVG content has been in...
CVE-2017-5389 High Yes Access restriction bypass
WebExtensions in Firefox < 51 could use the mozAddonManager API by modifying the CSP...
CVE-2017-5390 High Yes Privilege escalation
The JSON viewer in the Developer Tools in Firefox < 51 and Thunderbird < 45.7 uses insecure...
CVE-2017-5396 High Yes Arbitrary code execution
A use-after-free vulnerability has been found in the Media Decoder of Firefox < 51 and...