Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2005-3352

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

CVSS2: 4.3
EPSS: Высокий
ubuntu логотип

CVE-2005-3351

почти 21 год назад

SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3350

почти 21 год назад

libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3349

почти 21 год назад

GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2005-3348

почти 21 год назад

HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-3347

почти 21 год назад

Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2005-3346

почти 21 год назад

Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3345

больше 20 лет назад

rssh 2.0.0 through 2.2.3 allows local users to bypass access restrictions and gain root privileges by using the rssh_chroot_helper command to chroot to an external directory.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3344

почти 21 год назад

The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2005-3343

больше 20 лет назад

tkdiff before 4.1.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-3342

больше 20 лет назад

noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.

CVSS2: 1.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3341

больше 20 лет назад

DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh and (2) register-p.sh.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-3340

больше 20 лет назад

The tuxpaint-import.sh script in Tux Paint (tuxpaint) 0.9.14 and earlier creates temporary files insecurely, with unknown impact and attack vectors.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3339

почти 21 год назад

Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-3338

почти 21 год назад

Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-3337

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-3336

почти 21 год назад

SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3335

почти 21 год назад

PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-3334

почти 21 год назад

Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 parameters.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-3330

почти 21 год назад

The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-3352

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

CVSS2: 4.3
74%
Высокий
больше 20 лет назад
ubuntu логотип
CVE-2005-3351

SpamAssassin 3.0.4 allows attackers to bypass spam detection via an e-mail with a large number of recipients ("To" addresses), which triggers a bus error in Perl.

CVSS2: 5
7%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3350

libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.

CVSS2: 7.5
4%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3349

GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.

CVSS2: 1.9
0%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3348

HTTP response splitting vulnerability in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egroupware before 1.0.0.009, allows remote attackers to spoof web content and poison web caches via CRLF sequences in the charset parameter.

CVSS2: 4.3
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3347

Multiple directory traversal vulnerabilities in index.php in phpSysInfo 2.4 and earlier, as used in phpgroupware 0.9.16 and earlier, and egrouwpware before 1.0.0.009, allow remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) sensor_program parameter or the (2) _SERVER[HTTP_ACCEPT_LANGUAGE] parameter, which overwrites an internal variable, a variant of CVE-2003-0536. NOTE: due to a typo in an advisory, an issue in osh was inadvertently linked to this identifier; the proper identifier for the osh issue is CVE-2005-3346.

CVSS2: 6.8
4%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3346

Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbitrary environment variables, such as LD_PRELOAD, via pathname arguments of the form "$VAR/EVAR=arg", which cause the EVAR portion to be appended to a buffer returned by a getenv function call.

CVSS2: 7.2
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3345

rssh 2.0.0 through 2.2.3 allows local users to bypass access restrictions and gain root privileges by using the rssh_chroot_helper command to chroot to an external directory.

CVSS2: 7.2
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3344

The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.

CVSS2: 10
8%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3343

tkdiff before 4.1.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3342

noweb 2.10c and earlier allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.

CVSS2: 1.2
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3341

DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh and (2) register-p.sh.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3340

The tuxpaint-import.sh script in Tux Paint (tuxpaint) 0.9.14 and earlier creates temporary files insecurely, with unknown impact and attack vectors.

CVSS2: 7.2
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-3339

Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.

CVSS2: 7.2
0%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3338

Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.

CVSS2: 5
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3337

Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3336

SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3335

PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.

CVSS2: 7.5
7%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3334

Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 parameters.

CVSS2: 4.3
5%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-3330

The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, which is not properly handled by the fetch function.

CVSS2: 7.5
17%
Средний
почти 21 год назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.