Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2005-3341

около 20 лет назад

DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh and (2) register-p.sh.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-3340

около 20 лет назад

The tuxpaint-import.sh script in Tux Paint (tuxpaint) 0.9.14 and earlier creates temporary files insecurely, with unknown impact and attack vectors.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3339

больше 20 лет назад

Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3338

больше 20 лет назад

Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3337

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-3336

больше 20 лет назад

SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3335

больше 20 лет назад

PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3334

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 parameters.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2005-3330

больше 20 лет назад

The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-3325

больше 20 лет назад

Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to execute arbitrary SQL commands via the sig[1] parameter and possibly other parameters.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3323

больше 20 лет назад

docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3319

больше 20 лет назад

The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-3318

больше 20 лет назад

Buffer overflow in the _chm_decompress_block function in CHM lib (chmlib) before 0.37, as used in products such as KchmViewer, allows attackers to execute arbitrary code, a different vulnerability than CVE-2005-2930.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-3313

больше 20 лет назад

The IRC protocol dissector in Ethereal 0.10.13 allows remote attackers to cause a denial of service (infinite loop).

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3310

больше 20 лет назад

Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer, which renders malformed image types as HTML, enabling cross-site scripting (XSS) attacks. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer (CVE-2005-3312) and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in phpBB.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3303

больше 20 лет назад

The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3302

больше 20 лет назад

Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.

CVSS3: 7.3
EPSS: Низкий
ubuntu логотип

CVE-2005-3301

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2005-3300

больше 20 лет назад

The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3299

больше 20 лет назад

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-3341

DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh and (2) register-p.sh.

CVSS2: 2.1
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3340

The tuxpaint-import.sh script in Tux Paint (tuxpaint) 0.9.14 and earlier creates temporary files insecurely, with unknown impact and attack vectors.

CVSS2: 7.2
0%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-3339

Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

CVSS2: 7.2
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3338

Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3337

Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.

CVSS2: 4.3
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3336

SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3335

PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.

CVSS2: 7.5
7%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3334

Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 parameters.

CVSS2: 4.3
10%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-3330

The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.

CVSS2: 7.5
21%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-3325

Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to execute arbitrary SQL commands via the sig[1] parameter and possibly other parameters.

CVSS2: 7.5
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3323

docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3319

The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or VirtualHost.

CVSS2: 2.1
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3318

Buffer overflow in the _chm_decompress_block function in CHM lib (chmlib) before 0.37, as used in products such as KchmViewer, allows attackers to execute arbitrary code, a different vulnerability than CVE-2005-2930.

CVSS2: 5.1
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3313

The IRC protocol dissector in Ethereal 0.10.13 allows remote attackers to cause a denial of service (infinite loop).

CVSS2: 5
4%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3310

Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer, which renders malformed image types as HTML, enabling cross-site scripting (XSS) attacks. NOTE: it could be argued that this vulnerability is due to a design flaw in Internet Explorer (CVE-2005-3312) and the proper fix should be in that browser; if so, then this should not be treated as a vulnerability in phpBB.

CVSS2: 3.5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3303

The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.

CVSS2: 7.5
10%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3302

Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.

CVSS3: 7.3
6%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3301

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl3 allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) left.php, (2) queryframe.php, or (3) server_databases.php.

CVSS2: 4.3
12%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-3300

The register_globals emulation layer in grab_globals.php for phpMyAdmin before 2.6.4-pl3 does not perform safety checks on values in the _FILES array for uploaded files, which allows remote attackers to include arbitrary files by using direct requests to library scripts that do not use grab_globals.php, then modifying certain configuration values for the theme.

CVSS2: 5
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3299

PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.

CVSS2: 5
9%
Низкий
больше 20 лет назад

Уязвимостей на страницу