Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 74 393

Количество 74 393

ubuntu логотип

CVE-2005-0135

больше 21 года назад

The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0133

больше 21 года назад

ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0131

больше 21 года назад

The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0130

больше 21 года назад

Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0129

больше 21 года назад

The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-0117

больше 21 года назад

Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0116

больше 21 года назад

AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.

CVSS2: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2005-0111

больше 21 года назад

Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0109

больше 21 года назад

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

CVSS3: 5.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0108

больше 21 года назад

Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0107

больше 21 года назад

bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0106

больше 21 года назад

SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0105

больше 21 года назад

Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0104

больше 21 года назад

Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-0103

больше 21 года назад

PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0102

больше 21 года назад

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2005-0101

больше 21 года назад

Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-0100

больше 21 года назад

Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0099

больше 21 года назад

The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0097

больше 21 года назад

The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-0135

The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0133

ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.

CVSS2: 5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0131

The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.

CVSS2: 5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0130

Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0129

The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.

CVSS2: 7.5
10%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0117

Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0116

AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.

CVSS2: 7.5
75%
Высокий
больше 21 года назад
ubuntu логотип
CVE-2005-0111

Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0109

Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.

CVSS3: 5.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0108

Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.

CVSS2: 5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0107

bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0106

SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0105

Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.

CVSS2: 4.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0104

Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0103

PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0102

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.

CVSS3: 9.8
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0101

Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.

CVSS2: 7.5
16%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0100

Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0099

The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0097

The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.

CVSS2: 5
11%
Средний
больше 21 года назад

Уязвимостей на страницу