Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 59 371

Количество 59 371

ubuntu логотип

CVE-2007-2807

больше 18 лет назад

Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message.

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2007-2799

больше 18 лет назад

Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2007-2798

около 18 лет назад

Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.

CVSS2: 9
EPSS: Средний
ubuntu логотип

CVE-2007-2797

около 18 лет назад

xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2007-2789

больше 18 лет назад

The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-2768

больше 18 лет назад

OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-2756

больше 18 лет назад

The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-2754

больше 18 лет назад

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.

CVSS2: 6.8
EPSS: Средний
ubuntu логотип

CVE-2007-2748

больше 18 лет назад

The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-2741

больше 18 лет назад

Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.

CVSS2: 9.3
EPSS: Средний
ubuntu логотип

CVE-2007-2740

больше 18 лет назад

Unspecified vulnerability in xajax before 0.2.5 has unknown impact and attack vectors, not related to XSS.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-2728

больше 18 лет назад

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-2727

больше 18 лет назад

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2007-2721

больше 18 лет назад

The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-2693

больше 18 лет назад

MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2007-2692

больше 18 лет назад

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2007-2691

больше 18 лет назад

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2007-2683

больше 18 лет назад

Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2007-2671

больше 18 лет назад

Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access.

CVSS2: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2007-2654

больше 18 лет назад

xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.

CVSS2: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-2807

Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message.

CVSS2: 6.8
22%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-2799

Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted attackers to execute arbitrary code via a large file that triggers an overflow that bypasses an assert() statement. NOTE: this issue is due to an incorrect patch for CVE-2007-1536.

CVSS2: 5.1
3%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2798

Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.

CVSS2: 9
15%
Средний
около 18 лет назад
ubuntu логотип
CVE-2007-2797

xterm, including 192-7.el4 in Red Hat Enterprise Linux and 208-3.1 in Debian GNU/Linux, sets the wrong group ownership of tty devices, which allows local users to write data to other users' terminals.

CVSS2: 2.1
0%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-2789

The BMP image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Sun Java Runtime Environment in JDK and JRE 6, JDK and JRE 5.0 Update 10 and earlier, SDK and JRE 1.4.2_14 and earlier, and SDK and JRE 1.3.1_19 and earlier, when running on Unix/Linux systems, allows remote attackers to cause a denial of service (JVM hang) via untrusted applets or applications that open arbitrary local files via a crafted BMP file, such as /dev/tty.

CVSS2: 4.3
5%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2768

OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.

CVSS2: 4.3
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2756

The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.

CVSS2: 4.3
7%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2754

Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.

CVSS2: 6.8
47%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-2748

The substr_count function in PHP 5.2.1 and earlier allows context-dependent attackers to obtain sensitive information via unspecified vectors, a different affected function than CVE-2007-1375.

CVSS2: 4.3
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2741

Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.

CVSS2: 9.3
15%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-2740

Unspecified vulnerability in xajax before 0.2.5 has unknown impact and attack vectors, not related to XSS.

CVSS2: 6.8
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2728

The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.

CVSS2: 5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2727

The mcrypt_create_iv function in ext/mcrypt/mcrypt.c in PHP before 4.4.7, 5.2.1, and possibly 5.0.x and other PHP 5 versions, calls php_rand_r with an uninitialized seed variable and therefore always generates the same initialization vector (IV), which might allow context-dependent attackers to decrypt certain data more easily because of the guessable encryption keys.

CVSS2: 2.6
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2721

The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.

CVSS2: 4.3
8%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2693

MySQL before 5.1.18 allows remote authenticated users without SELECT privileges to obtain sensitive information from partitioned tables via an ALTER TABLE statement.

CVSS2: 3.5
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2692

The mysql_change_db function in MySQL 5.0.x before 5.0.40 and 5.1.x before 5.1.18 does not restore THD::db_access privileges when returning from SQL SECURITY INVOKER stored routines, which allows remote authenticated users to gain privileges.

CVSS2: 6
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2691

MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.

CVSS2: 4.9
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2683

Buffer overflow in Mutt 1.4.2 might allow local users to execute arbitrary code via "&" characters in the GECOS field, which triggers the overflow during alias expansion.

CVSS2: 3.5
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2671

Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access.

CVSS2: 7.1
7%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-2654

xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.

CVSS2: 4.4
0%
Низкий
больше 18 лет назад

Уязвимостей на страницу