Количество 59 256
Количество 59 256

CVE-2004-0077
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.

CVE-2004-0075
The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.

CVE-2004-0047
Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.

CVE-2004-0010
Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.

CVE-2004-0009
Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.

CVE-2004-0006
Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.

CVE-2004-0003
Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."

CVE-2003-1599
WordPress 0.7 allows remote execution of commands. / Wp-links / links.all.php. An attacker can inject a url in $ abspath and get remote execution of commands with the privileges of the server web (usually nobody).

CVE-2003-1598
WordPress 0.7 (b2 cafelog code) allows SQL injection. / Blog.header.php. $ posts not converted to an integer, so we can inject sql in this variable. In MySQL 4.x can use UNION and subselects to obtain privileges.

CVE-2003-1564
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack."

CVE-2003-1327

CVE-2003-0993

CVE-2003-0987

CVE-2003-0985

CVE-2003-0984

CVE-2003-0972

CVE-2003-0969

CVE-2003-0967
FreeRadius DoS

CVE-2003-0961

CVE-2003-0949
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2004-0077 The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985. | CVSS2: 7.2 | 0% Низкий | больше 21 года назад |
![]() | CVE-2004-0075 The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service. | CVSS2: 2.1 | 0% Низкий | больше 21 года назад |
![]() | CVE-2004-0047 Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges. | CVSS2: 4.6 | 0% Низкий | больше 21 года назад |
![]() | CVE-2004-0010 Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges. | CVSS2: 7.2 | 0% Низкий | больше 21 года назад |
![]() | CVE-2004-0009 Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user. | CVSS2: 7.5 | 1% Низкий | больше 21 года назад |
![]() | CVE-2004-0006 Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect. | CVSS2: 7.5 | 17% Средний | больше 21 года назад |
![]() | CVE-2004-0003 Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking." | CVSS2: 4.6 | 0% Низкий | больше 21 года назад |
![]() | CVE-2003-1599 WordPress 0.7 allows remote execution of commands. / Wp-links / links.all.php. An attacker can inject a url in $ abspath and get remote execution of commands with the privileges of the server web (usually nobody). | CVSS2: 7.5 | 1% Низкий | почти 11 лет назад |
![]() | CVE-2003-1598 WordPress 0.7 (b2 cafelog code) allows SQL injection. / Blog.header.php. $ posts not converted to an integer, so we can inject sql in this variable. In MySQL 4.x can use UNION and subselects to obtain privileges. | CVSS2: 7.5 | 1% Низкий | почти 11 лет назад |
![]() | CVE-2003-1564 libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the "billion laughs attack." | CVSS3: 6.5 | 1% Низкий | больше 21 года назад |
![]() | CVSS2: 9.3 | 1% Низкий | больше 21 года назад | |
![]() | CVSS2: 7.5 | 14% Средний | больше 21 года назад | |
![]() | CVSS2: 7.5 | 26% Средний | больше 21 года назад | |
![]() | CVSS2: 7.2 | 1% Низкий | больше 21 года назад | |
![]() | CVSS2: 4.6 | 0% Низкий | больше 21 года назад | |
![]() | CVSS2: 10 | 1% Низкий | больше 21 года назад | |
![]() | CVSS2: 7.5 | 2% Низкий | больше 21 года назад | |
![]() | CVE-2003-0967 FreeRadius DoS | CVSS2: 5 | 4% Низкий | больше 21 года назад |
![]() | CVSS2: 7.2 | 1% Низкий | больше 21 года назад | |
![]() | CVSS2: 4.6 | 0% Низкий | больше 21 года назад |
Уязвимостей на страницу