Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 69 878

Количество 69 878

ubuntu логотип

CVE-2004-0642

почти 22 года назад

Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0640

около 22 лет назад

Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-0623

больше 21 года назад

Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-0599

почти 22 года назад

Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0598

почти 22 года назад

The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0597

почти 22 года назад

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

CVSS2: 10
EPSS: Высокий
ubuntu логотип

CVE-2004-0591

около 22 лет назад

Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2004-0588

около 22 лет назад

Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and script via e-mail messages.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2004-0587

около 22 лет назад

Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0583

около 22 лет назад

The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0579

около 22 лет назад

Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2004-0565

больше 21 года назад

Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0564

больше 21 года назад

Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT designed to run setuid-root." Therefore this identifier applies *only* to those configurations and installations under which pppoe is run setuid root despite the developer's warnings.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0563

больше 21 года назад

The tspc.conf configuration file in freenet6 before 0.9.6 and before 1.0 on Debian Linux has world readable permissions, which could allow local users to gain sensitive information, such as a username and password.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0559

почти 22 года назад

The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0558

почти 22 года назад

The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2004-0557

около 22 лет назад

Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2004-0555

больше 21 года назад

Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0554

около 22 лет назад

Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0541

около 22 лет назад

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

CVSS2: 10
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2004-0642

Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.

CVSS2: 7.5
8%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0640

Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.

CVSS2: 10
4%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0623

Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

CVSS2: 10
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-0599

Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.

CVSS2: 5
6%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0598

The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.

CVSS2: 5
6%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0597

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

CVSS2: 10
83%
Высокий
почти 22 года назад
ubuntu логотип
CVE-2004-0591

Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script or HRML via (1) e-mail headers or (2) a message with a "message/delivery-status" MIME Content-Type.

CVSS2: 6.8
5%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0588

Cross-site scripting (XSS) vulnerability in the web mail module for Usermin 1.070 allows remote attackers to insert arbitrary HTML and script via e-mail messages.

CVSS2: 6.8
1%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0587

Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.

CVSS2: 2.1
0%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0583

The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers to conduct a brute force attack to guess user IDs and passwords.

CVSS2: 5
2%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0579

Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.

CVSS2: 7.2
0%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0565

Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-0564

Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT designed to run setuid-root." Therefore this identifier applies *only* to those configurations and installations under which pppoe is run setuid root despite the developer's warnings.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-0563

The tspc.conf configuration file in freenet6 before 0.9.6 and before 1.0 on Debian Linux has world readable permissions, which could allow local users to gain sensitive information, such as a username and password.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-0559

The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.

CVSS2: 2.1
0%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0558

The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of service (service hang) via a certain UDP packet to the IPP port.

CVSS2: 5
27%
Средний
почти 22 года назад
ubuntu логотип
CVE-2004-0557

Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.

CVSS2: 10
25%
Средний
около 22 лет назад
ubuntu логотип
CVE-2004-0555

Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-0554

Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.

CVSS2: 2.1
1%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0541

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

CVSS2: 10
71%
Высокий
около 22 лет назад

Уязвимостей на страницу