Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2005-2557

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-2556

больше 20 лет назад

core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2555

больше 20 лет назад

Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2553

больше 20 лет назад

The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2550

больше 20 лет назад

Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2549

больше 20 лет назад

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2548

больше 20 лет назад

vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snmpd.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2547

больше 20 лет назад

security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2536

больше 20 лет назад

pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2534

больше 20 лет назад

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2533

больше 20 лет назад

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2532

больше 20 лет назад

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2531

больше 20 лет назад

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2500

больше 20 лет назад

Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl protocol.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2499

больше 20 лет назад

slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2498

больше 20 лет назад

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2496

больше 20 лет назад

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2495

больше 20 лет назад

Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2494

больше 20 лет назад

kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-2493

больше 4 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2005. Notes: none

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-2557

Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE-2005-3090.

CVSS2: 4.3
10%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2556

core/database_api.php in Mantis 0.19.0a1 through 1.0.0a3, with register_globals enabled, allows remote attackers to connect to internal databases by modifying the g_db_type variable and monitoring the speed of responses, as identified by bug#0005956.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2555

Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2553

The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with the -i option on a 64-bit executable program.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2550

Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab.

CVSS2: 7.5
5%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2549

Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers.

CVSS2: 7.5
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2548

vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snmpd.

CVSS2: 5
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2547

security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2536

pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execute arbitrary commands via a malicious PostScript file.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2534

Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.

CVSS2: 2.6
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2533

OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number of spoofed MAC addresses.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2532

OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can not be decrypted.

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2531

OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and causes the error to be processed by the wrong client, which allows remote attackers to cause a denial of service (client disconnection) via a large number of failed authentication attempts.

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2500

Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl protocol.

CVSS2: 7.5
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2499

slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2498

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nested XML tags in a PHP document that should not be nested, which are injected into an eval function call, a different vulnerability than CVE-2005-1921.

CVSS2: 7.5
5%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2496

The xntpd ntp (ntpd) daemon before 4.2.0b, when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes xntpd to run with different privileges than intended.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2495

Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.

CVSS2: 5.1
4%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2494

kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.

CVSS2: 7.2
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2493

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2005. Notes: none

больше 4 лет назад

Уязвимостей на страницу