Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 686

Количество 63 686

ubuntu логотип

CVE-2012-0027

около 14 лет назад

The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2012-0024

около 14 лет назад

MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2012-0023

больше 13 лет назад

Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.

CVSS2: 9.3
EPSS: Средний
ubuntu логотип

CVE-2012-0022

около 14 лет назад

Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2012-0021

около 14 лет назад

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.

CVSS2: 2.6
EPSS: Средний
ubuntu логотип

CVE-2011-5327

больше 6 лет назад

In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2011-5326

больше 9 лет назад

imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-5325

больше 8 лет назад

Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-5321

почти 10 лет назад

The tty_open function in drivers/tty/tty_io.c in the Linux kernel before 3.1.1 mishandles a driver-lookup failure, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted access to a device file under the /dev/pts directory.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-5320

больше 8 лет назад

scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s.

CVSS3: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2011-5319

почти 11 лет назад

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site that listens for ondevicemotion events, a different vulnerability than CVE-2015-1231.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-5280

больше 11 лет назад

Multiple stack-based buffer overflows in BOINC 6.13.x allow remote attackers to cause a denial of service (crash) via a long trickle-up to (1) client/cs_trickle.cpp or (2) db/db_base.cpp.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-5276

почти 12 лет назад

SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote authenticated users to execute arbitrary SQL commands via the database_name parameter.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-5275

почти 12 лет назад

The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for context-dependent users to gain privileges.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-5274

почти 12 лет назад

The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the dtcpkg_directory parameter in a do_install action to dtc/.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-5273

почти 12 лет назад

Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the pkg parameter in a do_install action to dtc/.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-5272

почти 12 лет назад

SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the vps_note parameter to dtcadmin/logPushlet.php. NOTE: this issue was originally part of CVE-2011-3197, but that ID was SPLIT due to different researchers.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2011-5271

около 6 лет назад

Pacemaker before 1.1.6 configure script creates temporary files insecurely

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2011-5270

около 12 лет назад

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2011-5268

около 12 лет назад

connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple failed SSL handshakes, a different vulnerability than CVE-2013-4550. NOTE: this issue was SPLIT from CVE-2013-4550 because it is a different type of issue.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-0027

The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.

CVSS2: 5
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-0024

MaraDNS before 1.3.07.12 and 1.4.x before 1.4.08 computes hash values for DNS data without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted queries with the Recursion Desired (RD) bit set.

CVSS2: 7.8
1%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2012-0023

Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.

CVSS2: 9.3
12%
Средний
больше 13 лет назад
ubuntu логотип
CVE-2012-0022

Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote attackers to cause a denial of service (CPU consumption) via a request that contains many parameters and parameter values, a different vulnerability than CVE-2011-4858.

CVSS2: 5
23%
Средний
около 14 лет назад
ubuntu логотип
CVE-2012-0021

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (daemon crash) via a cookie that lacks both a name and a value.

CVSS2: 2.6
33%
Средний
около 14 лет назад
ubuntu логотип
CVE-2011-5327

In the Linux kernel before 3.1, an off by one in the drivers/target/loopback/tcm_loop.c tcm_loop_make_naa_tpg() function could result in at least memory corruption.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2011-5326

imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.

CVSS3: 7.5
1%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2011-5325

Directory traversal vulnerability in the BusyBox implementation of tar before 1.22.0 v5 allows remote attackers to point to files outside the current working directory via a symlink.

CVSS3: 7.5
4%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2011-5321

The tty_open function in drivers/tty/tty_io.c in the Linux kernel before 3.1.1 mishandles a driver-lookup failure, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted access to a device file under the /dev/pts directory.

CVSS3: 5.5
0%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2011-5320

scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s.

CVSS3: 6.2
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2011-5319

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site that listens for ondevicemotion events, a different vulnerability than CVE-2015-1231.

CVSS2: 5
0%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2011-5280

Multiple stack-based buffer overflows in BOINC 6.13.x allow remote attackers to cause a denial of service (crash) via a long trickle-up to (1) client/cs_trickle.cpp or (2) db/db_base.cpp.

CVSS2: 5
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2011-5276

SQL injection vulnerability in the drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote authenticated users to execute arbitrary SQL commands via the database_name parameter.

CVSS2: 6.5
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-5275

The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for context-dependent users to gain privileges.

CVSS2: 7.5
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-5274

The drawAdminTools_PackageInstaller function in shared/inc/forms/packager.php in Domain Technologie Control (DTC) before 0.32.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the dtcpkg_directory parameter in a do_install action to dtc/.

CVSS2: 7.5
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-5273

Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the pkg parameter in a do_install action to dtc/.

CVSS2: 6.5
1%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-5272

SQL injection vulnerability in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary SQL commands via the vps_note parameter to dtcadmin/logPushlet.php. NOTE: this issue was originally part of CVE-2011-3197, but that ID was SPLIT due to different researchers.

CVSS2: 6.5
0%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2011-5271

Pacemaker before 1.1.6 configure script creates temporary files insecurely

CVSS3: 5.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2011-5270

wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

CVSS2: 4
1%
Низкий
около 12 лет назад
ubuntu логотип
CVE-2011-5268

connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple failed SSL handshakes, a different vulnerability than CVE-2013-4550. NOTE: this issue was SPLIT from CVE-2013-4550 because it is a different type of issue.

CVSS2: 4.3
1%
Низкий
около 12 лет назад

Уязвимостей на страницу