Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 73 920

Количество 73 920

ubuntu логотип

CVE-2007-4659

почти 19 лет назад

The zend_alter_ini_entry function in PHP before 5.2.4 does not properly handle an interruption to the flow of execution triggered by a memory_limit violation, which has unknown impact and attack vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-4658

почти 19 лет назад

The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-4657

почти 19 лет назад

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-4656

почти 19 лет назад

backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2007-4652

почти 19 лет назад

The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2007-4650

почти 19 лет назад

Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using "linked items" in WebDAV and (b) Reupload modules.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2007-4631

почти 19 лет назад

The DataLoader::doStart function in dataloader.cpp in QGit 1.5.6 and other versions up to 2pre1 allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on temporary files with predictable filenames.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2007-4629

почти 19 лет назад

Buffer overflow in the processLine function in maptemplate.c in MapServer before 4.10.3 allows attackers to cause a denial of service and possibly execute arbitrary code via a mapfile with a long layer name, group name, or metadata entry name.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-4626

почти 19 лет назад

Unspecified vulnerability in Polipo before 1.0.2 allows remote attackers to cause a denial of service (daemon crash) via certain network traffic associated with entities larger than 2 Gb.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-4625

почти 19 лет назад

Polipo before 1.0.2 allows remote HTTP servers to cause a denial of service (daemon crash) by aborting the response to a POST request.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-4619

почти 19 лет назад

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2007-4601

почти 19 лет назад

A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-4596

почти 19 лет назад

The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval function. NOTE: this might only be a vulnerability in limited environments.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2007-4584

почти 19 лет назад

Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to the p_mode variable.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2007-4575

больше 18 лет назад

HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods."

CVSS2: 9.3
EPSS: Средний
ubuntu логотип

CVE-2007-4574

почти 19 лет назад

Unspecified vulnerability in the "stack unwinder fixes" in kernel in Red Hat Enterprise Linux 5, when running on AMD64 and Intel 64, allows local users to cause a denial of service via unknown vectors.

CVSS2: 4.7
EPSS: Низкий
ubuntu логотип

CVE-2007-4573

почти 19 лет назад

The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2007-4572

почти 19 лет назад

Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2007-4571

почти 19 лет назад

The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2007-4569

почти 19 лет назад

backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to bypass the password requirement and login to arbitrary accounts via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2007-4659

The zend_alter_ini_entry function in PHP before 5.2.4 does not properly handle an interruption to the flow of execution triggered by a memory_limit violation, which has unknown impact and attack vectors.

CVSS2: 7.5
3%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4658

The money_format function in PHP 5 before 5.2.4, and PHP 4 before 4.4.8, permits multiple (1) %i and (2) %n tokens, which has unknown impact and attack vectors, possibly related to a format string vulnerability.

CVSS2: 7.5
2%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4657

Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.

CVSS2: 7.5
3%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4656

backup-manager-upload in Backup Manager before 0.6.3 provides the FTP server hostname, username, and password as plaintext command line arguments during FTP uploads, which allows local users to obtain sensitive information by listing the process and its arguments, a different vulnerability than CVE-2007-2766.

CVSS2: 2.1
0%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4652

The session extension in PHP before 5.2.4 might allow local users to bypass open_basedir restrictions via a session file that is a symlink.

CVSS2: 4.4
1%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4650

Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock and replace items via unknown vectors in (a) the WebDAV module; and (4) edit unspecified data files using "linked items" in WebDAV and (b) Reupload modules.

CVSS2: 6.4
2%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4631

The DataLoader::doStart function in dataloader.cpp in QGit 1.5.6 and other versions up to 2pre1 allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on temporary files with predictable filenames.

CVSS2: 6.9
0%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4629

Buffer overflow in the processLine function in maptemplate.c in MapServer before 4.10.3 allows attackers to cause a denial of service and possibly execute arbitrary code via a mapfile with a long layer name, group name, or metadata entry name.

CVSS2: 7.5
3%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4626

Unspecified vulnerability in Polipo before 1.0.2 allows remote attackers to cause a denial of service (daemon crash) via certain network traffic associated with entities larger than 2 Gb.

CVSS2: 5
1%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4625

Polipo before 1.0.2 allows remote HTTP servers to cause a denial of service (daemon crash) by aborting the response to a POST request.

CVSS2: 4.3
1%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4619

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.

CVSS2: 9.3
7%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4601

A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information.

CVSS2: 5
2%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4596

The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute arbitrary code via the Perl eval function. NOTE: this might only be a vulnerability in limited environments.

CVSS2: 7.5
8%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4584

Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to the p_mode variable.

CVSS2: 10
15%
Средний
почти 19 лет назад
ubuntu логотип
CVE-2007-4575

HSQLDB before 1.8.0.9, as used in OpenOffice.org (OOo) 2 before 2.3.1, allows user-assisted remote attackers to execute arbitrary Java code via crafted database documents, related to "exposing static java methods."

CVSS2: 9.3
14%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-4574

Unspecified vulnerability in the "stack unwinder fixes" in kernel in Red Hat Enterprise Linux 5, when running on AMD64 and Intel 64, allows local users to cause a denial of service via unknown vectors.

CVSS2: 4.7
0%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4573

The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain privileges by triggering an out-of-bounds access to the system call table using the %RAX register.

CVSS2: 7.2
1%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4572

Stack-based buffer overflow in nmbd in Samba 3.0.0 through 3.0.26a, when configured as a Primary or Backup Domain controller, allows remote attackers to have an unknown impact via crafted GETDC mailslot requests, related to handling of GETDC logon server requests.

CVSS2: 9.3
6%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4571

The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.

CVSS2: 2.1
1%
Низкий
почти 19 лет назад
ubuntu логотип
CVE-2007-4569

backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to bypass the password requirement and login to arbitrary accounts via unspecified vectors.

CVSS2: 6.8
1%
Низкий
почти 19 лет назад

Уязвимостей на страницу