Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 62 125

Количество 62 125

ubuntu логотип

CVE-2009-1301

больше 16 лет назад

Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2009-1300

больше 16 лет назад

apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2009-1299

больше 15 лет назад

The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2009-1298

около 16 лет назад

The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and hang) via long IP packets, possibly related to the ip_defrag function.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2009-1297

около 16 лет назад

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2009-1296

больше 16 лет назад

The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk. NOTE: the log files are only readable by root.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2009-1295

больше 16 лет назад

Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2009-1285

больше 16 лет назад

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2009-1284

больше 16 лет назад

Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliography file.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2009-1274

больше 16 лет назад

Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows remote attackers to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buffer overflow.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-1273

больше 16 лет назад

pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-1272

больше 16 лет назад

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-1271

больше 16 лет назад

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2009-1270

больше 16 лет назад

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2009-1269

больше 16 лет назад

Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-1268

больше 16 лет назад

The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2009-1267

больше 16 лет назад

Unspecified vulnerability in the LDAP dissector in Wireshark 0.99.2 through 1.0.6, when running on Windows, allows remote attackers to cause a denial of service (crash) via unknown attack vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-1266

больше 16 лет назад

Unspecified vulnerability in Wireshark before 1.0.7 has unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2009-1265

больше 16 лет назад

Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2009-1255

больше 16 лет назад

The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2009-1301

Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.

CVSS2: 10
9%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1300

apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.

CVSS2: 10
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1299

The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file.

CVSS2: 6.9
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2009-1298

The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and hang) via long IP packets, possibly related to the ip_defrag function.

CVSS2: 7.8
2%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-1297

iscsi_discovery in open-iscsi in SUSE openSUSE 10.3 through 11.1 and SUSE Linux Enterprise (SLE) 10 SP2 and 11, and other operating systems, allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file that has a predictable name.

CVSS2: 4.4
0%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2009-1296

The eCryptfs support utilities (ecryptfs-utils) 73-0ubuntu6.1 on Ubuntu 9.04 stores the mount passphrase in installation logs, which might allow local users to obtain access to the filesystem by reading the log files from disk. NOTE: the log files are only readable by root.

CVSS2: 1.9
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1295

Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does not properly remove files from the application's crash-report directory, which allows local users to delete arbitrary files via unspecified vectors.

CVSS2: 1.9
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1285

Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

CVSS2: 7.5
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1284

Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliography file.

CVSS2: 5
16%
Средний
больше 16 лет назад
ubuntu логотип
CVE-2009-1274

Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows remote attackers to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buffer overflow.

CVSS2: 5
5%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1273

pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.

CVSS2: 5
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1272

The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

CVSS2: 5
2%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1271

The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

CVSS2: 5
10%
Средний
больше 16 лет назад
ubuntu логотип
CVE-2009-1270

libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

CVSS2: 7.8
3%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1269

Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.

CVSS2: 5
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1268

The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet.

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1267

Unspecified vulnerability in the LDAP dissector in Wireshark 0.99.2 through 1.0.6, when running on Windows, allows remote attackers to cause a denial of service (crash) via unknown attack vectors.

CVSS2: 5
1%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1266

Unspecified vulnerability in Wireshark before 1.0.7 has unknown impact and attack vectors.

CVSS2: 10
0%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1265

Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.

CVSS2: 5
2%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-1255

The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.

CVSS2: 5
2%
Низкий
больше 16 лет назад

Уязвимостей на страницу