Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 804

Количество 63 804

ubuntu логотип

CVE-2007-3280

больше 18 лет назад

The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access.

CVSS2: 9
EPSS: Средний
ubuntu логотип

CVE-2007-3279

больше 18 лет назад

PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC domain, which allows remote attackers to create and execute functions, as demonstrated by functions that perform local brute-force password guessing attacks, which may evade intrusion detection.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2007-3278

больше 18 лет назад

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2007-3257

больше 18 лет назад

Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-3238

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2007-3231

больше 18 лет назад

Buffer overflow in MeCab before 0.96 has unknown impact and attack vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-3227

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2007-3215

больше 18 лет назад

PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-3209

больше 18 лет назад

Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2007-3204

больше 18 лет назад

SQL injection vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.4-pre2 allows remote attackers to execute arbitrary SQL commands via the pass parameter. NOTE: this issue reportedly exists because of an initial incomplete fix for CVE-2007-3190. The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-3193

больше 18 лет назад

lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2007-3192

больше 18 лет назад

admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.

CVSS2: 9.4
EPSS: Низкий
ubuntu логотип

CVE-2007-3191

больше 18 лет назад

Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/test.php, which calls the phpinfo function.

CVSS2: 9.4
EPSS: Низкий
ubuntu логотип

CVE-2007-3190

больше 18 лет назад

Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-3189

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3181

больше 18 лет назад

Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2007-3165

больше 18 лет назад

Tor before 0.1.2.14 can construct circuits in which an entry guard is in the same family as the exit node, which might compromise the anonymity of traffic sources and destinations by exposing traffic to inappropriate remote observers.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-3163

больше 18 лет назад

Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-3155

больше 18 лет назад

Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whether this issue is already covered by another CVE identifier.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2007-3154

больше 18 лет назад

Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-3280

The Database Link library (dblink) in PostgreSQL 8.1 implements functions via CREATE statements that map to arbitrary libraries based on the C programming language, which allows remote authenticated superusers to map and execute a function from any library, as demonstrated by using the system function in libc.so.6 to gain shell access.

CVSS2: 9
49%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-3279

PostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC domain, which allows remote attackers to create and execute functions, as demonstrated by functions that perform local brute-force password guessing attacks, which may evade intrusion detection.

CVSS2: 10
3%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3278

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host parameter that proxies the connection from 127.0.0.1.

CVSS2: 6.9
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3257

Camel (camel-imap-folder.c) in the mailer component for Evolution Data Server 1.11 allows remote IMAP servers to execute arbitrary code via a negative SEQUENCE value in GData, which is used as an array index.

CVSS2: 6.8
3%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3238

Cross-site scripting (XSS) vulnerability in functions.php in the default theme in WordPress 2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the PATH_INFO (REQUEST_URI) to wp-admin/themes.php, a different vulnerability than CVE-2007-1622. NOTE: this might not cross privilege boundaries in some configurations, since the Administrator role has the unfiltered_html capability.

CVSS2: 6
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3231

Buffer overflow in MeCab before 0.96 has unknown impact and attack vectors.

CVSS2: 7.5
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3227

Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.

CVSS2: 4.3
13%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-3215

PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.

CVSS2: 6.8
4%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3209

Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS2: 7.8
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3204

SQL injection vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.4-pre2 allows remote attackers to execute arbitrary SQL commands via the pass parameter. NOTE: this issue reportedly exists because of an initial incomplete fix for CVE-2007-3190. The provenance of this information is unknown; the details are obtained solely from third party information.

CVSS2: 7.5
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3193

lib/WikiUser/LDAP.php in PhpWiki before 1.3.13p1, when the configuration lacks a nonzero PASSWORD_LENGTH_MINIMUM, might allow remote attackers to bypass authentication via an empty password, which causes ldap_bind to return true when used with certain LDAP implementations.

CVSS2: 10
5%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3192

admin/setup.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to read and modify configuration settings via a direct request.

CVSS2: 9.4
3%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3191

Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to obtain configuration information via a direct request to admin/adm/test.php, which calls the phpinfo function.

CVSS2: 9.4
6%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3190

Multiple SQL injection vulnerabilities in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user and (2) pass parameters.

CVSS2: 6.8
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3189

Cross-site scripting (XSS) vulnerability in auth.php in Just For Fun Network Management System (JFFNMS) 0.8.3 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

CVSS2: 4.3
7%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3181

Buffer overflow in fbserver.exe in Firebird SQL 2 before 2.0.1 allows remote attackers to execute arbitrary code via a large p_cnct_count value in a p_cnct structure in a connect (0x01) request to port 3050/tcp, related to "an InterBase version of gds32.dll."

CVSS2: 10
29%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-3165

Tor before 0.1.2.14 can construct circuits in which an entry guard is in the same family as the exit node, which might compromise the anonymity of traffic sources and destinations by exposing traffic to inappropriate remote observers.

CVSS2: 5
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3163

Incomplete blacklist vulnerability in the filemanager in Frederico Caldeira Knabben FCKeditor 2.4.2 allows remote attackers to upload arbitrary .php files via an alternate data stream syntax, as demonstrated by .php::$DATA filenames, a related issue to CVE-2006-0658.

CVSS2: 5
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3155

Unspecified vulnerability in eGroupWare before 1.2.107-2 has unknown impact and attack vectors related to ADOdb. NOTE: due to lack of details from the vendor, it is uncertain whether this issue is already covered by another CVE identifier.

CVSS2: 10
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-3154

Unspecified vulnerability in Walter Zorn wz_tooltip.js (aka wz_tooltips) before 4.01, as used by eGroupWare before 1.2.107-2 and other packages, has unknown impact and remote attack vectors.

CVSS2: 10
1%
Низкий
больше 18 лет назад

Уязвимостей на страницу