Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 73 810

Количество 73 810

ubuntu логотип

CVE-2004-0785

почти 22 года назад

Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly handled by the URL decoder.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0783

почти 22 года назад

Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0782

почти 22 года назад

Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0781

почти 22 года назад

Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2004-0772

почти 22 года назад

Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2004-0771

почти 22 года назад

Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2004-0769

около 22 лет назад

Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" option but also exploitable through "l" and "v", and fixed in header.c, a different issue than CVE-2004-0771.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-0768

почти 22 года назад

libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0755

почти 22 года назад

The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0754

почти 22 года назад

Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0753

почти 22 года назад

The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0752

почти 22 года назад

OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0751

почти 22 года назад

The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2004-0749

больше 21 года назад

The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0748

почти 22 года назад

mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2004-0747

почти 22 года назад

Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2004-0745

почти 22 года назад

LHA 1.14 and earlier allows attackers to execute arbitrary commands via a directory with shell metacharacters in its name.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-0718

около 22 лет назад

The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0707

около 22 лет назад

SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0705

около 22 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2004-0785

Multiple buffer overflows in Gaim before 0.82 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) Rich Text Format (RTF) messages, (2) a long hostname for the local system as obtained from DNS, or (3) a long URL that is not properly handled by the URL decoder.

CVSS2: 7.5
5%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0783

Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).

CVSS2: 7.5
9%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0782

Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).

CVSS2: 7.5
9%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0781

Cross-site scripting (XSS) vulnerability in list.cgi in the Icecast internal web server (icecast-server) 1.3.12 and earlier allows remote attackers to inject arbitrary web script via the UserAgent parameter.

CVSS2: 4.3
1%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0772

Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.

CVSS3: 9.8
7%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0771

Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long w (working directory) command line option, a different issue than CVE-2004-0769. NOTE: this issue may be REJECTED if there are not any cases in which LHA is setuid or is otherwise used across security boundaries.

CVSS2: 10
19%
Средний
почти 22 года назад
ubuntu логотип
CVE-2004-0769

Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" option but also exploitable through "l" and "v", and fixed in header.c, a different issue than CVE-2004-0771.

CVSS2: 10
7%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0768

libpng 1.2.5 and earlier does not properly calculate certain buffer offsets, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.

CVSS2: 7.5
3%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0755

The FileStore capability in CGI::Session for Ruby before 1.8.1, and possibly PStore, creates files with insecure permissions, which can allow local users to steal session information and hijack sessions.

CVSS2: 2.1
0%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0754

Integer overflow in Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the size variable in Groupware server messages.

CVSS2: 7.5
4%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0753

The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.

CVSS2: 5
6%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0752

OpenOffice (OOo) 1.1.2 creates predictable directory names with insecure permissions during startup, which may allow local users to read or list files of other users.

CVSS2: 2.1
1%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0751

The char_buffer_read function in the mod_ssl module for Apache 2.x, when using reverse proxying to an SSL server, allows remote attackers to cause a denial of service (segmentation fault).

CVSS2: 5
70%
Средний
почти 22 года назад
ubuntu логотип
CVE-2004-0749

The mod_authz_svn module in Subversion 1.0.7 and earlier does not properly restrict access to all metadata on unreadable paths, which could allow remote attackers to gain sensitive information via (1) svn log -v, (2) svn propget, or (3) svn blame, and other commands that follow renames.

CVSS2: 5
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-0748

mod_ssl in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (CPU consumption) by aborting an SSL connection in a way that causes an Apache child process to enter an infinite loop.

CVSS2: 5
22%
Средний
почти 22 года назад
ubuntu логотип
CVE-2004-0747

Buffer overflow in Apache 2.0.50 and earlier allows local users to gain apache privileges via a .htaccess file that causes the overflow during expansion of environment variables.

CVSS3: 7.8
2%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0745

LHA 1.14 and earlier allows attackers to execute arbitrary commands via a directory with shell metacharacters in its name.

CVSS2: 10
3%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0718

The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.

CVSS2: 7.5
2%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0707

SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to grant membership to any group to execute arbitrary SQL.

CVSS2: 7.5
1%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0705

Multiple cross-site scripting (XSS) vulnerabilities in (1) editcomponents.cgi, (2) editgroups.cgi, (3) editmilestones.cgi, (4) editproducts.cgi, (5) editusers.cgi, and (6) editversions.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allow remote attackers to execute arbitrary JavaScript as other users via a URL parameter.

CVSS2: 6.8
1%
Низкий
около 22 лет назад

Уязвимостей на страницу