Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 59 618

Количество 59 618

ubuntu логотип

CVE-2007-3996

около 18 лет назад

Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-3962

около 18 лет назад

Multiple stack-based buffer overflows in fsplib.c in fsplib before 0.9 might allow remote attackers to execute arbitrary code via (1) a long filename that is not properly handled by the fsp_readdir_native function when MAXNAMLEN is greater than 255, or (2) a long d_name directory (dirent) field in the fsp_readdir function.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-3961

около 18 лет назад

Off-by-one error in the fsp_readdir_r function in fsplib.c in fsplib before 0.9 allows remote attackers to cause a denial of service via a directory entry whose length is exactly MAXNAMELEN, which prevents a terminating null byte from being added.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-3956

около 18 лет назад

TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a request to login.tscmd on TCP port 14534.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-3950

около 18 лет назад

lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3949

около 18 лет назад

mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.

CVSS2: 8.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3948

около 18 лет назад

connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3947

около 18 лет назад

request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.

CVSS2: 5.8
EPSS: Средний
ubuntu логотип

CVE-2007-3946

около 18 лет назад

mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2007-3930

около 18 лет назад

Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2007-3929

около 18 лет назад

Use-after-free vulnerability in the BitTorrent support in Opera before 9.22 allows user-assisted remote attackers to execute arbitrary code via a crafted header in a torrent file, which leaves a dangling pointer to an invalid object.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3922

около 18 лет назад

Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-3921

почти 18 лет назад

gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.

CVSS2: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3920

почти 18 лет назад

GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.

CVSS2: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2007-3919

почти 18 лет назад

(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2007-3918

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3917

почти 18 лет назад

The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters that can produce an invalid UTF-8 string after it is truncated, which triggers an uncaught exception, involving the truncate_message function in server/server.cpp. NOTE: this issue affects both clients and servers.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-3916

почти 18 лет назад

The main function in skkdic-expr.c in SKK Tools 1.2 allows local users to overwrite or delete arbitrary files via a symlink attack on a skkdic$PID temporary file.

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2007-3915

почти 6 лет назад

Mondo 2.24 has insecure handling of temporary files.

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2007-3913

около 18 лет назад

SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-3996

Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.

CVSS2: 6.8
6%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3962

Multiple stack-based buffer overflows in fsplib.c in fsplib before 0.9 might allow remote attackers to execute arbitrary code via (1) a long filename that is not properly handled by the fsp_readdir_native function when MAXNAMLEN is greater than 255, or (2) a long d_name directory (dirent) field in the fsp_readdir function.

CVSS2: 7.5
8%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3961

Off-by-one error in the fsp_readdir_r function in fsplib.c in fsplib before 0.9 allows remote attackers to cause a denial of service via a directory entry whose length is exactly MAXNAMELEN, which prevents a terminating null byte from being added.

CVSS2: 5
2%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3956

TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which allows remote attackers to cause a denial of service (CPU and memory consumption) via long username and password parameters in a request to login.tscmd on TCP port 14534.

CVSS2: 7.8
6%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3950

lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules.

CVSS2: 4.3
2%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3949

mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.

CVSS2: 8.3
1%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3948

connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts.

CVSS2: 4.3
2%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3947

request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.

CVSS2: 5.8
13%
Средний
около 18 лет назад
ubuntu логотип
CVE-2007-3946

mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header.

CVSS2: 6.4
4%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3930

Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML document identification and script execution by Internet Explorer even though the Content-Type header is text/plain.

CVSS2: 4.3
17%
Средний
около 18 лет назад
ubuntu логотип
CVE-2007-3929

Use-after-free vulnerability in the BitTorrent support in Opera before 9.22 allows user-assisted remote attackers to execute arbitrary code via a crafted header in a torrent file, which leaves a dangling pointer to an invalid object.

CVSS2: 9.3
7%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3922

Unspecified vulnerability in the Java Runtime Environment (JRE) Applet Class Loader in Sun JDK and JRE 5.0 Update 11 and earlier, 6 through 6 Update 1, and SDK and JRE 1.4.2_14 and earlier, allows remote attackers to violate the security model for an applet's outbound connections by connecting to certain localhost services running on the machine that loaded the applet.

CVSS2: 6.8
4%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2007-3921

gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.

CVSS2: 3.3
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-3920

GNOME screensaver 2.20 in Ubuntu 7.10, when used with Compiz, does not properly reserve input focus, which allows attackers with physical access to take control of the session after entering an Alt-Tab sequence, a related issue to CVE-2007-3069.

CVSS2: 6.2
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-3919

(1) xenbaked and (2) xenmon.py in Xen 3.1 and earlier allow local users to truncate arbitrary files via a symlink attack on /tmp/xenq-shm.

CVSS2: 6
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-3918

Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.

CVSS2: 4.3
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-3917

The multiplayer engine in Wesnoth 1.2.x before 1.2.7 and 1.3.x before 1.3.9 allows remote servers to cause a denial of service (crash) via a long message with multibyte characters that can produce an invalid UTF-8 string after it is truncated, which triggers an uncaught exception, involving the truncate_message function in server/server.cpp. NOTE: this issue affects both clients and servers.

CVSS2: 7.8
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-3916

The main function in skkdic-expr.c in SKK Tools 1.2 allows local users to overwrite or delete arbitrary files via a symlink attack on a skkdic$PID temporary file.

CVSS2: 4.4
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-3915

Mondo 2.24 has insecure handling of temporary files.

CVSS3: 9.1
0%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2007-3913

SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
0%
Низкий
около 18 лет назад

Уязвимостей на страницу