Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 59 244

Количество 59 244

ubuntu логотип

CVE-2006-2272

больше 19 лет назад

Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chunks.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2006-2271

больше 19 лет назад

The ECNE chunk handling in Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via an unexpected chunk when the session is in CLOSED state.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2006-2260

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-2247

больше 19 лет назад

WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-2237

больше 19 лет назад

The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.

CVSS2: 5.1
EPSS: Критический
ubuntu логотип

CVE-2006-2230

больше 19 лет назад

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than CVE-2006-1905. In addition, if the only attack vectors involve a user-assisted, local command line argument of a non-setuid program, this issue might not be a vulnerability.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-2224

больше 19 лет назад

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2006-2223

больше 19 лет назад

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2006-2220

больше 18 лет назад

phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-2219

больше 18 лет назад

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode functions, which displays the installation path in the resulting error message.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-2213

больше 19 лет назад

Hostapd 0.3.7-2 allows remote attackers to cause a denial of service (segmentation fault) via an unspecified value in the key_data_length field of an EAPoL frame.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-2200

около 19 лет назад

Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the (1) send_command, (2) string_utf16, (3) get_data, and (4) get_media_packet functions, and possibly other functions.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2006-2199

около 19 лет назад

Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.

CVSS2: 7.6
EPSS: Средний
ubuntu логотип

CVE-2006-2198

около 19 лет назад

OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.

CVSS2: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2006-2197

около 19 лет назад

Integer overflow in wv2 before 0.2.3 might allow context-dependent attackers to execute arbitrary code via a crafted Microsoft Word document.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2006-2196

около 19 лет назад

Unspecified vulnerability in pinball 0.3.1 allows local users to gain privileges via unknown attack vectors that cause pinball to load plugins from an attacker-controlled directory while operating at raised privileges.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2006-2195

около 19 лет назад

Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2006-2194

около 19 лет назад

The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2006-2193

около 19 лет назад

Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-2169

больше 19 лет назад

RT: Request Tracker 3.5.HEAD allows remote attackers to obtain sensitive information via the Rows parameter in Dist/Display.html, which reveals the installation path in an error message.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2006-2272

Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via incoming IP fragmented (1) COOKIE_ECHO and (2) HEARTBEAT SCTP control chunks.

CVSS2: 7.8
8%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2271

The ECNE chunk handling in Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (kernel panic) via an unexpected chunk when the session is in CLOSED state.

CVSS2: 7.8
8%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2260

Cross-site scripting (XSS) vulnerability in the project module (project.module) in Drupal 4.5 and 4.6 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 4.3
0%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2247

WebCalendar 1.0.1 to 1.0.3 generates different error messages depending on whether or not a username is valid, which allows remote attackers to enumerate valid usernames.

CVSS2: 5
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2237

The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.

CVSS2: 5.1
91%
Критический
больше 19 лет назад
ubuntu логотип
CVE-2006-2230

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than CVE-2006-1905. In addition, if the only attack vectors involve a user-assisted, local command line argument of a non-setuid program, this issue might not be a vulnerability.

CVSS2: 5
1%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2224

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.

CVSS2: 5
18%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2006-2223

RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

CVSS2: 5
14%
Средний
больше 19 лет назад
ubuntu логотип
CVE-2006-2220

phpBB 2.0.20 does not properly verify user-specified input variables used as limits to SQL queries, which allows remote attackers to obtain sensitive information via a negative LIMIT specification, as demonstrated by the start parameter to memberlist.php, which reveals the SQL query in the resulting error message.

CVSS2: 5
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-2219

phpBB 2.0.20 does not verify user-specified input variable types before being passed to type-dependent functions, which allows remote attackers to obtain sensitive information, as demonstrated by the (1) mode parameter to memberlist.php and the (2) highlight parameter to viewtopic.php that are used as an argument to the htmlspecialchars or urlencode functions, which displays the installation path in the resulting error message.

CVSS2: 5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2006-2213

Hostapd 0.3.7-2 allows remote attackers to cause a denial of service (segmentation fault) via an unspecified value in the key_data_length field of an EAPoL frame.

CVSS2: 5
2%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2006-2200

Stack-based buffer overflow in libmms, as used by (a) MiMMS 0.0.9 and (b) xine-lib 1.1.0 and earlier, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the (1) send_command, (2) string_utf16, (3) get_data, and (4) get_media_packet functions, and possibly other functions.

CVSS2: 5.1
4%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-2199

Unspecified vulnerability in Java Applets in OpenOffice.org 1.1.x (aka StarOffice) up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to escape the Java sandbox and conduct unauthorized activities via certain applets in OpenOffice documents.

CVSS2: 7.6
10%
Средний
около 19 лет назад
ubuntu логотип
CVE-2006-2198

OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an OpenOffice document with a malicious BASIC macro, which is executed without prompting the user.

CVSS2: 7.6
8%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-2197

Integer overflow in wv2 before 0.2.3 might allow context-dependent attackers to execute arbitrary code via a crafted Microsoft Word document.

CVSS2: 6.5
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-2196

Unspecified vulnerability in pinball 0.3.1 allows local users to gain privileges via unknown attack vectors that cause pinball to load plugins from an attacker-controlled directory while operating at raised privileges.

CVSS2: 4.6
0%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-2195

Cross-site scripting (XSS) vulnerability in horde 3 (horde3) before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via (1) templates/problem/problem.inc and (2) test.php.

CVSS2: 6.8
4%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-2194

The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper from dropping privileges.

CVSS2: 7.2
0%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-2193

Buffer overflow in the t2p_write_pdf_string function in tiff2pdf in libtiff 3.8.2 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TIFF file with a DocumentName tag that contains UTF-8 characters, which triggers the overflow when a character is sign extended to an integer that produces more digits than expected in an sprintf call.

CVSS2: 7.5
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-2169

RT: Request Tracker 3.5.HEAD allows remote attackers to obtain sensitive information via the Rows parameter in Dist/Display.html, which reveals the installation path in an error message.

CVSS2: 5
0%
Низкий
больше 19 лет назад

Уязвимостей на страницу