Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2005-2919

почти 21 год назад

libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2918

почти 21 год назад

The open_cmd_tube function in mount.c for gtkdiskfree 1.9.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the gtkdiskfree temporary file.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2917

почти 21 год назад

Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2878

почти 21 год назад

Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-2877

почти 21 год назад

The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.

CVSS2: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2005-2876

почти 21 год назад

umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and other flags.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-2875

почти 21 год назад

Py2Play allows remote attackers to execute arbitrary Python code via pickled objects, which Py2Play unpickles and executes.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2874

почти 21 год назад

The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2873

почти 21 год назад

The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX, which can cause ipt_recent netfilter rules to block too early, a different vulnerability than CVE-2005-2872.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2872

почти 21 год назад

The ipt_recent kernel module (ipt_recent.c) in Linux kernel before 2.6.12, when running on 64-bit processors such as AMD64, allows remote attackers to cause a denial of service (kernel panic) via certain attacks such as SSH brute force, which leads to memset calls using a length based on the u_int32_t type, acting on an array of unsigned long elements, a different vulnerability than CVE-2005-2873.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2871

почти 21 год назад

Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-2869

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-2851

почти 21 год назад

smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2820

почти 21 год назад

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]".

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-2808

почти 21 год назад

frox 0.7.16 and 0.7.17 does not properly parse certain Deny ACLs, which might allow attackers to bypass intended restrictions and access blocked hosts.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2807

почти 21 год назад

frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-2802

почти 21 год назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2872, CVE-2005-2873. Reason: this candidate's description originally combined two separate issues. Notes: All CVE users should consult CVE-2005-2872 and CVE-2005-2873 to determine the appropriate identifier for the issue

EPSS: Низкий
ubuntu логотип

CVE-2005-2801

почти 21 год назад

xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2800

почти 21 год назад

Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2798

почти 21 год назад

sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-2919

libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable.

CVSS2: 5
4%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2918

The open_cmd_tube function in mount.c for gtkdiskfree 1.9.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the gtkdiskfree temporary file.

CVSS2: 5
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2917

Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

CVSS2: 5
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2878

Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.

CVSS2: 7.5
15%
Средний
почти 21 год назад
ubuntu логотип
CVE-2005-2877

The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev parameter to TWikiUsers.

CVSS2: 7.5
71%
Высокий
почти 21 год назад
ubuntu логотип
CVE-2005-2876

umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and other flags.

CVSS2: 7.2
0%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2875

Py2Play allows remote attackers to execute arbitrary Python code via pickled objects, which Py2Play unpickles and executes.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2874

The is_path_absolute function in scheduler/client.c for the daemon in CUPS before 1.1.23 allows remote attackers to cause a denial of service (CPU consumption by tight loop) via a "..\.." URL in an HTTP request.

CVSS2: 5
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2873

The ipt_recent kernel module (ipt_recent.c) in Linux kernel 2.6.12 and earlier does not properly perform certain time tests when the jiffies value is greater than LONG_MAX, which can cause ipt_recent netfilter rules to block too early, a different vulnerability than CVE-2005-2872.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2872

The ipt_recent kernel module (ipt_recent.c) in Linux kernel before 2.6.12, when running on 64-bit processors such as AMD64, allows remote attackers to cause a denial of service (kernel panic) via certain attacks such as SSH brute force, which leads to memset calls using a length based on the u_int32_t type, acting on an array of unsigned long elements, a different vulnerability than CVE-2005-2873.

CVSS2: 5
4%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2871

Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.

CVSS2: 7.5
21%
Средний
почти 21 год назад
ubuntu логотип
CVE-2005-2869

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.

CVSS2: 4.3
5%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2851

smb4k 0.4 and other versions before 0.6.3 allows local users to read sensitive files via a symlink attack on the (1) smb4k.tmp or (2) sudoers temporary files.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2820

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message containing Internet Explorer "Conditional Comments" such as "[if]" and "[endif]".

CVSS2: 4.3
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2808

frox 0.7.16 and 0.7.17 does not properly parse certain Deny ACLs, which might allow attackers to bypass intended restrictions and access blocked hosts.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2807

frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.

CVSS2: 7.2
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2802

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-2872, CVE-2005-2873. Reason: this candidate's description originally combined two separate issues. Notes: All CVE users should consult CVE-2005-2872 and CVE-2005-2873 to determine the appropriate identifier for the issue

почти 21 год назад
ubuntu логотип
CVE-2005-2801

xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.

CVSS3: 7.5
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2800

Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not properly handled when the next() iterator returns NULL or an error.

CVSS2: 2.1
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2798

sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.

CVSS2: 5
2%
Низкий
почти 21 год назад

Уязвимостей на страницу