Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 646

Количество 63 646

ubuntu логотип

CVE-2005-4667

около 20 лет назад

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

CVSS2: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2005-4644

около 20 лет назад

Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-4639

около 20 лет назад

Buffer overflow in the CA-driver (dst_ca.c) for TwinHan DST Frontend/Card in Linux kernel 2.6.12 and other versions before 2.6.15 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by "reading more than 8 bytes into an 8 byte long array".

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-4636

около 20 лет назад

OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-4635

около 20 лет назад

The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink messages.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-4618

около 20 лет назад

Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer. NOTE: since the sysctl is called from a userland program that provides the argument, this might not be a vulnerability, unless a legitimate user-assisted or setuid scenario can be identified.

CVSS2: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2005-4605

около 20 лет назад

The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-4604

около 20 лет назад

Buffer overflow in MTink in the printer-filters-utils package allows local users to execute arbitrary code via a long HOME environment variable.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2005-4601

около 20 лет назад

The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-4592

около 20 лет назад

Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are longer than the input buffer used by flex.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-4591

около 20 лет назад

Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter or bogolexer converts character sets.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-4585

около 20 лет назад

Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2005-4584

около 20 лет назад

BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL (\0) character.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-4560

около 20 лет назад

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.

CVSS2: 7.5
EPSS: Критический
ubuntu логотип

CVE-2005-4536

около 20 лет назад

Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-4534

около 20 лет назад

The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-4533

около 20 лет назад

Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via "getopt" style argument specifications, which are not filtered.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-4532

около 20 лет назад

scponlyc in scponly 4.1 and earlier, when the operating system supports LD_PRELOAD mechanisms, allows local users to execute arbitrary code with root privileges by creating a chroot directory in their home directory, hard linking to a system setuid application, and using a modified LD_PRELOAD to modify expected function calls in the setuid application.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-4524

около 20 лет назад

Mantis 1.0.0rc3 does not properly handle "Make note private" when a bug is being resolved, which has unknown impact and attack vectors, probably related to an information leak.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-4523

около 20 лет назад

Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-4667

Buffer overflow in UnZip 5.50 and earlier allows user-assisted attackers to execute arbitrary code via a long filename command line argument. NOTE: since the overflow occurs in a non-setuid program, there are not many scenarios under which it poses a vulnerability, unless unzip is passed long arguments when it is invoked from other programs.

CVSS2: 3.7
3%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4644

Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.

CVSS2: 4.3
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4639

Buffer overflow in the CA-driver (dst_ca.c) for TwinHan DST Frontend/Card in Linux kernel 2.6.12 and other versions before 2.6.15 allows local users to cause a denial of service (crash) and possibly execute arbitrary code by "reading more than 8 bytes into an 8 byte long array".

CVSS2: 4.6
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4636

OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.

CVSS2: 4.6
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4635

The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink messages.

CVSS2: 5
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4618

Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer. NOTE: since the sysctl is called from a userland program that provides the argument, this might not be a vulnerability, unless a legitimate user-assisted or setuid scenario can be identified.

CVSS2: 3.6
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4605

The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value.

CVSS2: 2.1
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4604

Buffer overflow in MTink in the printer-filters-utils package allows local users to execute arbitrary code via a long HOME environment variable.

CVSS2: 10
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4601

The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command.

CVSS2: 7.5
12%
Средний
около 20 лет назад
ubuntu логотип
CVE-2005-4592

Heap-based buffer overflow in bogofilter and bogolexer 0.96.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via words that are longer than the input buffer used by flex.

CVSS2: 7.5
4%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4591

Heap-based buffer overflow in bogofilter 0.96.2, 0.95.2, 0.94.14, 0.94.12, and other versions from 0.93.5 to 0.96.2, when using Unicode databases, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "invalid input sequences" that lead to heap corruption when bogofilter or bogolexer converts character sets.

CVSS2: 7.5
5%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4585

Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

CVSS2: 7.8
5%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4584

BZFlag server 2.0.4 and earlier allows remote attackers to cause a denial of service (application crash) via a callsign that is not followed by a NULL (\0) character.

CVSS2: 5
10%
Средний
около 20 лет назад
ubuntu логотип
CVE-2005-4560

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.

CVSS2: 7.5
90%
Критический
около 20 лет назад
ubuntu логотип
CVE-2005-4536

Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file.

CVSS2: 2.1
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4534

The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 7.5
2%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4533

Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via "getopt" style argument specifications, which are not filtered.

CVSS2: 7.5
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4532

scponlyc in scponly 4.1 and earlier, when the operating system supports LD_PRELOAD mechanisms, allows local users to execute arbitrary code with root privileges by creating a chroot directory in their home directory, hard linking to a system setuid application, and using a modified LD_PRELOAD to modify expected function calls in the setuid application.

CVSS2: 7.2
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4524

Mantis 1.0.0rc3 does not properly handle "Make note private" when a bug is being resolved, which has unknown impact and attack vectors, probably related to an information leak.

CVSS2: 5
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-4523

Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.

CVSS2: 5
1%
Низкий
около 20 лет назад

Уязвимостей на страницу