Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2005-2797

почти 21 год назад

OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" option) when a listen address is not provided, which may cause OpenSSH to enable the GatewayPorts functionality.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2796

почти 21 год назад

The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2794

почти 21 год назад

store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2793

почти 21 год назад

PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2792

почти 21 год назад

Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-2781

почти 21 год назад

The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2772

почти 21 год назад

Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-2769

почти 21 год назад

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-2728

почти 21 год назад

The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-2724

почти 21 год назад

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been disputed by the developer.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-2718

почти 21 год назад

Buffer overflow in ad_pcm.c in MPlayer 1.0pre7 and earlier allows remote attackers to execute arbitrary code via crafted PCM audio data, as demonstrated using a video file with an audio header containing a large value in a stream format (strf) chunk.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2717

почти 21 год назад

PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2716

почти 21 год назад

The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a Bluetooth device name.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2709

почти 21 год назад

The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2708

почти 21 год назад

The search_binary_handler function in exec.c in Linux 2.4 kernel on 64-bit x86 architectures does not check a return code for a particular function call when virtual memory is low, which allows local users to cause a denial of service (panic), as demonstrated by running a process using the bash ulimit -v command.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2707

почти 21 год назад

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2706

почти 21 год назад

Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2005-2705

почти 21 год назад

Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2704

почти 21 год назад

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2703

почти 21 год назад

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-2797

OpenSSH 4.0, and other versions before 4.2, does not properly handle dynamic port forwarding ("-D" option) when a listen address is not provided, which may cause OpenSSH to enable the GatewayPorts functionality.

CVSS2: 5
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2796

The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.

CVSS2: 5
8%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2794

store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.

CVSS2: 5
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2793

PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter.

CVSS2: 7.5
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2792

Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the custom_welcome_page parameter.

CVSS2: 5
12%
Средний
почти 21 год назад
ubuntu логотип
CVE-2005-2781

The Avatar upload feature in FUD Forum before 2.7.0 does not properly verify uploaded files, which allows remote attackers to execute arbitrary PHP code via a file with a .php extension that contains image data followed by PHP code.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2772

Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.

CVSS2: 7.5
10%
Средний
почти 21 год назад
ubuntu логотип
CVE-2005-2769

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing tags with strings that contain ">" or other special characters, which is not properly sanitized by SqWebMail.

CVSS2: 4.3
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2728

The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.

CVSS2: 5
11%
Средний
почти 21 год назад
ubuntu логотип
CVE-2005-2724

Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attachment that is processed by the Display feature. NOTE: the severity of this issue has been disputed by the developer.

CVSS2: 4.3
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2718

Buffer overflow in ad_pcm.c in MPlayer 1.0pre7 and earlier allows remote attackers to execute arbitrary code via crafted PCM audio data, as demonstrated using a video file with an audio header containing a large value in a stream format (strf) chunk.

CVSS2: 7.5
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2717

PHP remote file inclusion vulnerability in WebCalendar before 1.0.1 allows remote attackers to execute arbitrary PHP code when opening settings.php, possibly via send_reminders.php or other scripts.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2716

The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a Bluetooth device name.

CVSS2: 7.5
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2709

The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, then obtaining and modifying function pointers in memory that was used for the ctl_table.

CVSS2: 4.6
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2708

The search_binary_handler function in exec.c in Linux 2.4 kernel on 64-bit x86 architectures does not check a return code for a particular function call when virtual memory is low, which allows local users to cause a denial of service (panic), as demonstrated by running a process using the bash ulimit -v command.

CVSS2: 2.1
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2707

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.

CVSS2: 5
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2706

Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.

CVSS2: 6.4
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2705

Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.

CVSS2: 7.5
4%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2704

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.

CVSS2: 5
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2703

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.

CVSS2: 5
2%
Низкий
почти 21 год назад

Уязвимостей на страницу