Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 59 371

Количество 59 371

ubuntu логотип

CVE-2006-3411

около 19 лет назад

TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2006-3410

около 19 лет назад

Tor before 0.1.1.20 creates "internal circuits" primarily consisting of nodes with "useful exit nodes," which allows remote attackers to conduct unspecified statistical attacks.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-3409

около 19 лет назад

Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer overflow when elements are added to smartlists.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-3408

около 19 лет назад

Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an unspecified denial of service via unknown vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-3407

около 19 лет назад

Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2006-3404

около 19 лет назад

Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2006-3403

около 19 лет назад

The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2006-3392

около 19 лет назад

Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2006-3390

около 19 лет назад

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-3389

около 19 лет назад

index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-3388

около 19 лет назад

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the table parameter.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2006-3379

около 19 лет назад

Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-3378

около 19 лет назад

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2006-3376

около 19 лет назад

Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a WMF file.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2006-3360

около 19 лет назад

Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-3355

около 19 лет назад

Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an incomplete patch for CVE-2004-0982.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-3336

около 19 лет назад

TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2006-3334

около 19 лет назад

Buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng before 1.2.12 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors related to "chunk error processing," possibly involving the "chunk_name".

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-3320

около 19 лет назад

Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the command parameter.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-3311

почти 19 лет назад

Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.

CVSS2: 5.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2006-3411

TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, which makes it easier for remote attackers to conduct brute force attacks on the encryption keys.

CVSS2: 6.4
0%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3410

Tor before 0.1.1.20 creates "internal circuits" primarily consisting of nodes with "useful exit nodes," which allows remote attackers to conduct unspecified statistical attacks.

CVSS2: 5
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3409

Integer overflow in Tor before 0.1.1.20 allows remote attackers to execute arbitrary code via crafted large inputs, which result in a buffer overflow when elements are added to smartlists.

CVSS2: 7.5
5%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3408

Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an unspecified denial of service via unknown vectors.

CVSS2: 5
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3407

Tor before 0.1.1.20 allows remote attackers to spoof log entries or possibly execute shell code via strings with non-printable characters.

CVSS2: 6.4
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3404

Buffer overflow in the xcf_load_vector function in app/xcf/xcf-load.c for gimp before 2.2.12 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XCF file with a large num_axes value in the VECTORS property.

CVSS2: 5.1
2%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3403

The smdb daemon (smbd/service.c) in Samba 3.0.1 through 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of share connection requests.

CVSS2: 5
30%
Средний
около 19 лет назад
ubuntu логотип
CVE-2006-3392

Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote attackers to read arbitrary files, as demonstrated using "..%01" sequences, which bypass the removal of "../" sequences before bytes such as "%01" are removed from the filename. NOTE: This is a different issue than CVE-2006-3274.

CVSS2: 5
72%
Высокий
около 19 лет назад
ubuntu логотип
CVE-2006-3390

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.

CVSS2: 5
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3389

index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third party who states that the issue does not leak any target-specific information.

CVSS2: 5
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3388

Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the table parameter.

CVSS2: 5.8
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3379

Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case.

CVSS2: 5
2%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3378

passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.

CVSS2: 7.2
0%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3376

Integer overflow in player.c in libwmf 0.2.8.4, as used in multiple products including (1) wv, (2) abiword, (3) freetype, (4) gimp, (5) libgsf, and (6) imagemagick allows remote attackers to execute arbitrary code via the MaxRecordSize header field in a WMF file.

CVSS2: 7.5
12%
Средний
около 19 лет назад
ubuntu логотип
CVE-2006-3360

Directory traversal vulnerability in index.php in phpSysInfo 2.5.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) sequence and a trailing null (%00) byte in the lng parameter, which will display a different error message if the file exists.

CVSS2: 5
9%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3355

Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being used with the strncpy function. NOTE: This appears to be the result of an incomplete patch for CVE-2004-0982.

CVSS2: 7.5
7%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3336

TWiki 01-Dec-2000 up to 4.0.3 allows remote attackers to bypass the upload filter and execute arbitrary code via filenames with double extensions such as ".php.en", ".php.1", and other allowed extensions that are not .txt. NOTE: this is only a vulnerability when the server allows script execution in the pub directory.

CVSS2: 4
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3334

Buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng before 1.2.12 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors related to "chunk error processing," possibly involving the "chunk_name".

CVSS2: 7.5
2%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3320

Cross-site scripting (XSS) vulnerability in command.php in SiteBar 3.3.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the command parameter.

CVSS2: 2.6
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-3311

Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.

CVSS2: 5.1
58%
Средний
почти 19 лет назад

Уязвимостей на страницу