Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 59 541

Количество 59 541

ubuntu логотип

CVE-2007-0473

больше 18 лет назад

The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2007-0472

больше 18 лет назад

Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K's lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn't properly handled by the writeFile function in core/smb4kfileio.cpp.

CVSS2: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2007-0469

больше 18 лет назад

The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2007-0461

больше 18 лет назад

Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-0460

больше 18 лет назад

Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2007-0459

больше 18 лет назад

packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-0458

больше 18 лет назад

Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-0457

больше 18 лет назад

Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-0456

больше 18 лет назад

Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-0455

больше 18 лет назад

Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-0454

больше 18 лет назад

Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-0453

больше 18 лет назад

Buffer overflow in the nss_winbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2007-0452

больше 18 лет назад

smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-0451

больше 18 лет назад

Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2007-0450

больше 18 лет назад

Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2007-0448

больше 18 лет назад

The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2007-0406

больше 18 лет назад

Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cause a denial of service (daemon crash) or gain privileges via a long HOME environment variable. NOTE: some of these details are obtained from third party information.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2007-0405

больше 18 лет назад

The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2007-0404

больше 18 лет назад

bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-0387

больше 18 лет назад

SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-0473

The writeFile function in core/smb4kfileio.cpp in Smb4K before 0.8.0 does not preserve /etc/sudoers permissions across modifications, which allows local users to obtain sensitive information (/etc/sudoers contents) by reading this file.

CVSS2: 1.9
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0472

Multiple race conditions in Smb4K before 0.8.0 allow local users to (1) modify arbitrary files via unspecified manipulations of Smb4K's lock file, which is not properly handled by the remove_lock_file function in core/smb4kfileio.cpp, and (2) add lines to the sudoers file via a symlink attack on temporary files, which isn't properly handled by the writeFile function in core/smb4kfileio.cpp.

CVSS2: 3.7
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0469

The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.

CVSS2: 9.3
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0461

Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors.

CVSS2: 5
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0460

Multiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to "improper string length calculations."

CVSS2: 10
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0459

packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.

CVSS2: 5
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0458

Unspecified vulnerability in the HTTP dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors, a different issue than CVE-2006-5468.

CVSS2: 4.3
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0457

Unspecified vulnerability in the IEEE 802.11 dissector in Wireshark (formerly Ethereal) 0.10.14 through 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 4.3
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0456

Unspecified vulnerability in the LLT dissector in Wireshark (formerly Ethereal) 0.99.3 and 0.99.4 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS2: 4.3
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0455

Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.

CVSS2: 7.5
4%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0454

Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.

CVSS2: 7.5
5%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0453

Buffer overflow in the nss_winbind.so.1 library in Samba 3.0.21 through 3.0.23d, as used in the winbindd daemon on Solaris, allows attackers to execute arbitrary code via the (1) gethostbyname and (2) getipnodebyname functions.

CVSS2: 4.6
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0452

smbd in Samba 3.0.6 through 3.0.23d allows remote authenticated users to cause a denial of service (memory and CPU exhaustion) by renaming a file in a way that prevents a request from being removed from the deferred open queue, which triggers an infinite loop.

CVSS2: 6.8
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0451

Apache SpamAssassin before 3.1.8 allows remote attackers to cause a denial of service via long URLs in malformed HTML, which triggers "massive memory usage."

CVSS2: 4.3
25%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-0450

Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.

CVSS2: 5
86%
Высокий
больше 18 лет назад
ubuntu логотип
CVE-2007-0448

The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path specified with an invalid URI, as demonstrated via the srpath URI.

CVSS2: 10
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0406

Multiple buffer overflows in the (1) main function in (a) client.c, and the (2) server_setup and (3) server_client_connect functions in (b) server.c in gxine 0.5.9 and earlier allow local users to cause a denial of service (daemon crash) or gain privileges via a long HOME environment variable. NOTE: some of these details are obtained from third party information.

CVSS2: 4.6
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0405

The LazyUser class in the AuthenticationMiddleware for Django 0.95 does not properly cache the user name across requests, which allows remote authenticated users to gain the privileges of a different user.

CVSS2: 6.5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0404

bin/compile-messages.py in Django 0.95 does not quote argument strings before invoking the msgfmt program through the os.system function, which allows attackers to execute arbitrary commands via shell metacharacters in a (1) .po or (2) .mo file.

CVSS2: 7.5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0387

SQL injection vulnerability in models/category.php in the Weblinks component for Joomla! SVN 20070118 (com_weblinks) allows remote attackers to execute arbitrary SQL commands via the catid parameter.

CVSS2: 7.5
0%
Низкий
больше 18 лет назад

Уязвимостей на страницу