Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 62 331

Количество 62 331

ubuntu логотип

CVE-2010-0011

почти 16 лет назад

The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arbitrary commands via JavaScript code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-0010

почти 16 лет назад

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2010-0009

больше 15 лет назад

Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-0008

почти 16 лет назад

The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2010-0007

почти 16 лет назад

net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2010-0006

почти 16 лет назад

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue to CVE-2007-4567.

CVSS2: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2010-0005

почти 16 лет назад

query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2010-0004

почти 16 лет назад

ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-0003

почти 16 лет назад

The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then reading a log file, and might allow local users to cause a denial of service (system slowdown or crash) by jumping to an address.

CVSS2: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2010-0002

почти 16 лет назад

The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the existence of a file, via a crafted filename.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2010-0001

почти 16 лет назад

Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2009-NNN5

больше 15 лет назад

EPSS: Низкий
ubuntu логотип

CVE-2009-NNN4

около 16 лет назад

EPSS: Низкий
ubuntu логотип

CVE-2009-NNN3

около 16 лет назад

EPSS: Низкий
ubuntu логотип

CVE-2009-NNN2

около 16 лет назад

EPSS: Низкий
ubuntu логотип

CVE-2009-5155

почти 7 лет назад

In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2009-5147

больше 8 лет назад

DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

CVSS3: 7.3
EPSS: Средний
ubuntu логотип

CVE-2009-5146

почти 6 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

EPSS: Низкий
ubuntu логотип

CVE-2009-5145

больше 8 лет назад

Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2009-5144

почти 8 лет назад

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2010-0011

The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arbitrary commands via JavaScript code.

CVSS2: 7.5
1%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-0010

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.

CVSS2: 6.8
47%
Средний
почти 16 лет назад
ubuntu логотип
CVE-2010-0009

Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.

CVSS2: 4.3
1%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2010-0008

The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.

CVSS2: 7.8
4%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-0007

net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.

CVSS2: 2.1
0%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-0006

The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue to CVE-2007-4567.

CVSS2: 7.1
2%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-0005

query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.

CVSS2: 7.5
0%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-0004

ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.

CVSS2: 5
1%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-0003

The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then reading a log file, and might allow local users to cause a denial of service (system slowdown or crash) by jumping to an address.

CVSS2: 5.4
0%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-0002

The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the existence of a file, via a crafted filename.

CVSS2: 2.1
0%
Низкий
почти 16 лет назад
ubuntu логотип
CVE-2010-0001

Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.

CVSS2: 6.8
38%
Средний
почти 16 лет назад
ubuntu логотип
больше 15 лет назад
ubuntu логотип
около 16 лет назад
ubuntu логотип
около 16 лет назад
ubuntu логотип
около 16 лет назад
ubuntu логотип
CVE-2009-5155

In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2009-5147

DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

CVSS3: 7.3
52%
Средний
больше 8 лет назад
ubuntu логотип
CVE-2009-5146

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

почти 6 лет назад
ubuntu логотип
CVE-2009-5145

Cross-site scripting (XSS) vulnerability in ZMI pages that use the manage_tabs_message in Zope 2.11.4, 2.11.2, 2.10.9, 2.10.7, 2.10.6, 2.10.5, 2.10.4, 2.10.2, 2.10.1, 2.12.

CVSS3: 6.1
1%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2009-5144

mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.

CVSS3: 7.5
0%
Низкий
почти 8 лет назад

Уязвимостей на страницу