Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 686

Количество 63 686

ubuntu логотип

CVE-2005-2627

больше 20 лет назад

Multiple integer underflows in Kismet before 2005-08-R1 allow remote attackers to execute arbitrary code via (1) kernel headers in a pcap file or (2) data frame dissection, which leads to heap-based buffer overflows.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2626

больше 20 лет назад

Unspecified vulnerability in Kismet before 2005-08-R1 allows remote attackers to have an unknown impact via unprintable characters in the SSID.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2005-2617

больше 20 лет назад

The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with crafted ELF headers.

CVSS2: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2612

больше 20 лет назад

Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.

CVSS2: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2005-2602

больше 20 лет назад

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2600

больше 20 лет назад

FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2596

больше 20 лет назад

User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2573

больше 20 лет назад

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2572

больше 20 лет назад

MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute arbitrary code via (1) a request for a non-library file, which causes the Windows LoadLibraryEx function to block, or (2) a request for a function in a library that has the XXX_deinit or XXX_init functions defined but is not tailored for mySQL, such as jpeg1x32.dll and jpeg2x32.dll.

CVSS2: 8.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2558

больше 20 лет назад

Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.

CVSS2: 4.6
EPSS: Средний
ubuntu логотип

CVE-2005-2557

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-2556

больше 20 лет назад

core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2555

больше 20 лет назад

Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2553

больше 20 лет назад

The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2550

больше 20 лет назад

Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2549

больше 20 лет назад

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2548

больше 20 лет назад

vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snmpd.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2547

больше 20 лет назад

security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2536

больше 20 лет назад

pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2534

больше 20 лет назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-2627

Multiple integer underflows in Kismet before 2005-08-R1 allow remote attackers to execute arbitrary code via (1) kernel headers in a pcap file or (2) data frame dissection, which leads to heap-based buffer overflows.

CVSS2: 7.5
6%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2626

Unspecified vulnerability in Kismet before 2005-08-R1 allows remote attackers to have an unknown impact via unprintable characters in the SSID.

CVSS2: 10
4%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2617

The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with crafted ELF headers.

CVSS2: 3.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2612

Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.

CVSS2: 7.5
73%
Высокий
больше 20 лет назад
ubuntu логотип
CVE-2005-2602

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.

CVSS2: 2.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2600

FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2596

User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2573

The mysql_create_function function in sql_udf.cc for MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta, when running on Windows, uses an incomplete blacklist in a directory traversal check, which allows attackers to include arbitrary files via the backslash (\) character.

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2572

MySQL, when running on Windows, allows remote authenticated users with insert privileges on the mysql.func table to cause a denial of service (server hang) and possibly execute arbitrary code via (1) a request for a non-library file, which causes the Windows LoadLibraryEx function to block, or (2) a request for a function in a library that has the XXX_deinit or XXX_init functions defined but is not tailored for mySQL, such as jpeg1x32.dll and jpeg2x32.dll.

CVSS2: 8.5
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2558

Stack-based buffer overflow in the init_syms function in MySQL 4.0 before 4.0.25, 4.1 before 4.1.13, and 5.0 before 5.0.7-beta allows remote authenticated users who can create user-defined functions to execute arbitrary code via a long function_name field.

CVSS2: 4.6
15%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-2557

Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.

CVSS2: 4.3
10%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2556

core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2555

Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2553

The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2550

Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.

CVSS2: 7.5
5%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2549

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.

CVSS2: 7.5
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2548

vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snmpd.

CVSS2: 5
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2547

security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2536

pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
1%
Низкий
больше 20 лет назад

Уязвимостей на страницу