Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2005-3623

около 20 лет назад

nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3622

около 20 лет назад

phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3621

около 20 лет назад

CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3590

почти 7 лет назад

The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corrupt memory.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2005-3573

около 20 лет назад

Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to cause a denial of service (application crash).

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3570

около 20 лет назад

Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-3559

около 20 лет назад

Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3540

около 20 лет назад

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3539

около 20 лет назад

Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-3538

около 20 лет назад

hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3537

около 20 лет назад

A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3536

около 20 лет назад

SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3535

около 20 лет назад

Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary code via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3534

около 20 лет назад

Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-3533

около 20 лет назад

Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3532

около 20 лет назад

authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3531

около 20 лет назад

fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-3527

больше 20 лет назад

Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2005-3524

больше 20 лет назад

Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2005-3523

больше 20 лет назад

Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-3623

nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.

CVSS2: 5
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3622

phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.

CVSS2: 5
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3621

CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts.

CVSS2: 5
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3590

The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corrupt memory.

CVSS3: 9.8
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2005-3573

Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to cause a denial of service (application crash).

CVSS2: 5
6%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3570

Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".

CVSS2: 4.3
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3559

Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.

CVSS2: 5
6%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3540

Buffer overflow in petris before 1.0.1 allows remote attackers to execute arbitrary code via unspecified attack vectors.

CVSS2: 7.5
4%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3539

Multiple eval injection vulnerabilities in HylaFAX 4.2.3 and earlier allow remote attackers to execute arbitrary commands via (1) the notify script in HylaFAX 4.2.0 to 4.2.3 and (2) crafted CallID parameters to the faxrcvd script in HylaFAX 4.2.2 and 4.2.3.

CVSS2: 7.5
31%
Средний
около 20 лет назад
ubuntu логотип
CVE-2005-3538

hfaxd in HylaFAX 4.2.3, when PAM support is disabled, accepts arbitrary passwords, which allows remote attackers to gain privileges.

CVSS2: 7.5
2%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3537

A "missing request validation" error in phpBB 2 before 2.0.18 allows remote attackers to edit private messages of other users, probably by modifying certain parameters or other inputs.

CVSS2: 5
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3536

SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

CVSS2: 7.5
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3535

Buffer overflow in KETM 0.0.6 allows local users to execute arbitrary code via unknown vectors.

CVSS2: 7.5
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3534

Buffer overflow in the Network Block Device (nbd) server 2.7.5 and earlier, and 2.8.0 through 2.8.2, allows remote attackers to execute arbitrary code via a large request, which is written past the end of the buffer because nbd does not account for memory taken by the reply header.

CVSS2: 7.5
14%
Средний
около 20 лет назад
ubuntu логотип
CVE-2005-3533

Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.

CVSS2: 7.2
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3532

authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be granted, which allows attackers to authenticate to the server using accounts that have been disabled.

CVSS2: 7.5
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3531

fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain special characters.

CVSS2: 2.1
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3527

Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP.

CVSS2: 4
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3524

Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.

CVSS2: 10
25%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-3523

Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field.

CVSS2: 7.5
25%
Средний
больше 20 лет назад

Уязвимостей на страницу