361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
802
This Week
23 results · Page 1/1
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification failed back then.
debian
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
debian
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.
debian · canonical
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
devscripts_devel_team · fedoraproject