Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2006-1168

около 20 лет назад

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-1165

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data."

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-1150

больше 20 лет назад

Buffer overflow in Tenes Empanadas Graciela (TEG) 0.11.1, automatically appends an _ (underscore) to the end of duplicate nicknames, which allows remote attackers to cause a denial of service (application crash) by creating multiple users with long, identical nicknames, which triggers an off-by-one error.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2006-1119

больше 20 лет назад

fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2006-1095

больше 20 лет назад

Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2006-1066

больше 20 лет назад

Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during the do_debug function call.

CVSS2: 1.2
EPSS: Низкий
ubuntu логотип

CVE-2006-1064

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-1063

больше 20 лет назад

Unspecified vulnerability in Lurker 2.0 and earlier allows remote attackers to create or overwrite files in any writable directory that is named "mbox".

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-1062

больше 20 лет назад

Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-1061

больше 20 лет назад

Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-1060

больше 20 лет назад

Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-1059

больше 20 лет назад

The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.

CVSS2: 1.2
EPSS: Низкий
ubuntu логотип

CVE-2006-1058

больше 20 лет назад

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2006-1057

больше 20 лет назад

Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.

CVSS2: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2006-1056

больше 20 лет назад

The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2006-1055

больше 20 лет назад

The fill_write_buffer function in sysfs/file.c in Linux kernel 2.6.12 up to versions before 2.6.17-rc1 does not zero terminate a buffer when a length of PAGE_SIZE or more is requested, which might allow local users to cause a denial of service (crash) by causing an out-of-bounds read.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2006-1052

больше 20 лет назад

The selinux_ptrace logic in hooks.c in SELinux for Linux 2.6.6 allows local users with ptrace permissions to change the tracer SID to an SID of another process.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2006-1046

больше 20 лет назад

server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2006-1045

больше 20 лет назад

The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-1017

больше 20 лет назад

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2006-1168

The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow.

CVSS2: 7.5
6%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2006-1165

Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data."

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1150

Buffer overflow in Tenes Empanadas Graciela (TEG) 0.11.1, automatically appends an _ (underscore) to the end of duplicate nicknames, which allows remote attackers to cause a denial of service (application crash) by creating multiple users with long, identical nicknames, which triggers an off-by-one error.

CVSS2: 7.8
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1119

fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.

CVSS2: 4
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1095

Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie.

CVSS2: 7.2
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1066

Linux kernel 2.6.16-rc2 and earlier, when running on x86_64 systems with preemption enabled, allows local users to cause a denial of service (oops) via multiple ptrace tasks that perform single steps, which can cause corruption of the DEBUG_STACK stack during the do_debug function call.

CVSS2: 1.2
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1064

Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

CVSS2: 2.6
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1063

Unspecified vulnerability in Lurker 2.0 and earlier allows remote attackers to create or overwrite files in any writable directory that is named "mbox".

CVSS2: 5
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1062

Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown vectors.

CVSS2: 5
2%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1061

Heap-based buffer overflow in cURL and libcURL 7.15.0 through 7.15.2 allows remote attackers to execute arbitrary commands via a TFTP URL (tftp://) with a valid hostname and a long path.

CVSS2: 7.5
5%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1060

Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.

CVSS2: 7.5
4%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1059

The winbindd daemon in Samba 3.0.21 to 3.0.21c writes the machine trust account password in cleartext in log files, which allows local users to obtain the password and spoof the server in the domain.

CVSS2: 1.2
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1058

BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.

CVSS3: 5.5
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1057

Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file.

CVSS2: 3.7
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1056

The Linux kernel before 2.6.16.9 and the FreeBSD kernel, when running on AMD64 and other 7th and 8th generation AuthenticAMD processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one process to determine portions of the state of floating point instructions of other processes, which can be leveraged to obtain sensitive information such as cryptographic keys. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1055

The fill_write_buffer function in sysfs/file.c in Linux kernel 2.6.12 up to versions before 2.6.17-rc1 does not zero terminate a buffer when a length of PAGE_SIZE or more is requested, which might allow local users to cause a denial of service (crash) by causing an out-of-bounds read.

CVSS2: 4.9
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1052

The selinux_ptrace logic in hooks.c in SELinux for Linux 2.6.6 allows local users with ptrace permissions to change the tracer SID to an SID of another process.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1046

server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.

CVSS2: 5
5%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1045

The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.

CVSS2: 2.6
5%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2006-1017

The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2) open_basedir functions, and when used in applications that accept user-controlled input for the mailbox argument to the imap_open function, allow remote attackers to obtain access to an IMAP stream data structure and conduct unauthorized IMAP actions.

CVSS2: 9.3
3%
Низкий
больше 20 лет назад

Уязвимостей на страницу