Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2005-1751

больше 20 лет назад

Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.

CVSS2: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2005-1740

больше 20 лет назад

fixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute arbitrary commands, or overwrite arbitrary files via a symlink attack.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2005-1739

больше 20 лет назад

The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-1705

больше 20 лет назад

gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-1704

больше 20 лет назад

Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-1692

больше 20 лет назад

Format string vulnerability in gxine 0.4.1 through 0.4.4, and other versions down to 0.3, allows remote attackers to execute arbitrary code via a ram file with a URL whose hostname contains format string specifiers.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-1689

больше 20 лет назад

Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2005-1688

больше 20 лет назад

Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2005-1686

больше 20 лет назад

Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-1679

больше 20 лет назад

Stack-based buffer overflow in the error directive in picasm 1.12b and earlier allows attackers to execute arbitrary code via a long error message.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-1636

больше 20 лет назад

mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-1589

больше 20 лет назад

The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-1565

больше 20 лет назад

Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-1564

больше 20 лет назад

post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-1563

больше 20 лет назад

Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-1546

больше 20 лет назад

Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-1545

больше 20 лет назад

Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-1544

больше 20 лет назад

Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-1532

больше 20 лет назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-1531

больше 20 лет назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-1751

Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.

CVSS2: 3.7
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1740

fixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute arbitrary commands, or overwrite arbitrary files via a symlink attack.

CVSS2: 10
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1739

The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.

CVSS2: 5
12%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-1705

gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.

CVSS2: 7.2
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1704

Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1692

Format string vulnerability in gxine 0.4.1 through 0.4.4, and other versions down to 0.3, allows remote attackers to execute arbitrary code via a ram file with a URL whose hostname contains format string specifiers.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1689

Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.

CVSS3: 9.8
55%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-1688

Wordpress 1.5 and earlier allows remote attackers to obtain sensitive information via a direct request to files in (1) wp-content/themes/, (2) wp-includes/, or (3) wp-admin/, which reveal the path in an error message.

CVSS3: 5.3
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1686

Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.

CVSS2: 2.6
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1679

Stack-based buffer overflow in the error directive in picasm 1.12b and earlier allows attackers to execute arbitrary code via a long error message.

CVSS2: 5.1
5%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1636

mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1589

The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264.

CVSS2: 7.2
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1565

Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1564

post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1563

Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1546

Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.

CVSS2: 5.1
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1545

Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow.

CVSS2: 5.1
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1544

Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.

CVSS2: 7.5
16%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-1532

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

CVSS2: 7.5
17%
Средний
больше 20 лет назад
ubuntu логотип
CVE-2005-1531

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
2%
Низкий
больше 20 лет назад

Уязвимостей на страницу