Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2005-3389

больше 20 лет назад

The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3388

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2005-3359

около 20 лет назад

The atm module in Linux kernel 2.6 before 2.6.14 allows local users to cause a denial of service (panic) via certain socket calls that produce inconsistent reference counts for loadable protocol modules.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2005-3358

около 20 лет назад

Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bitmask, which causes a panic when a page fault occurs.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2005-3357

около 20 лет назад

mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.

CVSS2: 5.4
EPSS: Средний
ubuntu логотип

CVE-2005-3356

около 20 лет назад

The mq_open system call in Linux kernel 2.6.9, in certain situations, can decrement a counter twice ("double decrement") as a result of multiple calls to the mntput function when the dentry_open function call fails, which allows local users to cause a denial of service (panic) via unspecified attack vectors.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-3355

около 20 лет назад

Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters, and cookie values".

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2005-3354

около 20 лет назад

Stack-based buffer overflow in the ldif_get_line function in ldif.c of Sylpheed before 2.1.6 allows user-assisted attackers to execute arbitrary code by having local users import LDIF files with long lines.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-3353

около 20 лет назад

The exif_read_data function in the Exif module in PHP before 4.4.1 allows remote attackers to cause a denial of service (infinite loop) via a malformed JPEG image.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-3352

около 20 лет назад

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2005-3351

около 20 лет назад

SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-3350

больше 20 лет назад

libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3349

около 20 лет назад

GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2005-3348

около 20 лет назад

HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-3347

около 20 лет назад

Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2005-3346

около 20 лет назад

Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3345

около 20 лет назад

rssh 2.0.0 through 2.2.3 allows local users to bypass access restrictions and gain root privileges by using the rssh_chroot_helper command to chroot to an external directory.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3344

около 20 лет назад

The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2005-3343

около 20 лет назад

tkdiff before 4.1.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-3342

около 20 лет назад

noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.

CVSS2: 1.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-3389

The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an internal flag that enables register_globals and allows attackers to exploit vulnerabilities in PHP applications that would otherwise be protected.

CVSS2: 5
10%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3388

Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."

CVSS2: 4.3
63%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-3359

The atm module in Linux kernel 2.6 before 2.6.14 allows local users to cause a denial of service (panic) via certain socket calls that produce inconsistent reference counts for loadable protocol modules.

CVSS2: 4.9
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3358

Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bitmask, which causes a panic when a page fault occurs.

CVSS2: 4.9
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3357

mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL pointer dereference.

CVSS2: 5.4
43%
Средний
около 20 лет назад
ubuntu логотип
CVE-2005-3356

The mq_open system call in Linux kernel 2.6.9, in certain situations, can decrement a counter twice ("double decrement") as a result of multiple calls to the mntput function when the dentry_open function call fails, which allows local users to cause a denial of service (panic) via unspecified attack vectors.

CVSS2: 2.1
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3355

Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters, and cookie values".

CVSS2: 6.4
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3354

Stack-based buffer overflow in the ldif_get_line function in ldif.c of Sylpheed before 2.1.6 allows user-assisted attackers to execute arbitrary code by having local users import LDIF files with long lines.

CVSS2: 5.1
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3353

The exif_read_data function in the Exif module in PHP before 4.4.1 allows remote attackers to cause a denial of service (infinite loop) via a malformed JPEG image.

CVSS2: 5
19%
Средний
около 20 лет назад
ubuntu логотип
CVE-2005-3352

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

CVSS2: 4.3
37%
Средний
около 20 лет назад
ubuntu логотип
CVE-2005-3351

SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.

CVSS2: 5
18%
Средний
около 20 лет назад
ubuntu логотип
CVE-2005-3350

libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.

CVSS2: 7.5
4%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3349

GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.

CVSS2: 1.9
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3348

HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.

CVSS2: 4.3
2%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3347

Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.

CVSS2: 6.8
3%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3346

Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.

CVSS2: 7.2
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3345

rssh 2.0.0 through 2.2.3 allows local users to bypass access restrictions and gain root privileges by using the rssh_chroot_helper command to chroot to an external directory.

CVSS2: 7.2
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3344

The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.

CVSS2: 10
10%
Средний
около 20 лет назад
ubuntu логотип
CVE-2005-3343

tkdiff before 4.1.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.6
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3342

noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.

CVSS2: 1.2
0%
Низкий
около 20 лет назад

Уязвимостей на страницу