Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2005-2360

около 21 года назад

Unknown vulnerability in the LDAP dissector in Ethereal 0.8.5 through 0.10.11 allows remote attackers to cause a denial of service (free static memory and application crash) via unknown attack vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2359

около 21 года назад

The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2353

около 21 года назад

run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2352

почти 7 лет назад

I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2351

почти 7 лет назад

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2349

почти 7 лет назад

Zoo 2.10 has Directory traversal

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2337

почти 21 год назад

Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2336

почти 21 год назад

Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via "missing pages" in which the page name is not properly escaped, a different vulnerability than CVE-2005-2803.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-2335

около 21 года назад

Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses. NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2320

около 21 года назад

WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2317

около 21 года назад

Shorewall 2.4.x before 2.4.1, 2.2.x before 2.2.5, and 2.0.x before 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with an accepted MAC address to bypass other firewall rules or policies.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2302

около 21 года назад

PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-2301

около 21 года назад

PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2295

около 21 года назад

NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero datablock size.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2277

около 21 года назад

Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2005-2270

около 21 года назад

Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2269

около 21 года назад

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2268

около 21 года назад

Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2267

около 21 года назад

Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-2266

около 21 года назад

Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-2360

Unknown vulnerability in the LDAP dissector in Ethereal 0.8.5 through 0.10.11 allows remote attackers to cause a denial of service (free static memory and application crash) via unknown attack vectors.

CVSS2: 5
2%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2359

The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec session.

CVSS2: 5
1%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2353

run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 2.1
0%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2352

I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.

CVSS3: 8.1
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2005-2351

Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.

CVSS3: 5.5
0%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2005-2349

Zoo 2.10 has Directory traversal

CVSS3: 7.5
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2005-2337

Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).

CVSS2: 7.5
3%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2336

Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via "missing pages" in which the page name is not properly escaped, a different vulnerability than CVE-2005-2803.

CVSS2: 4.3
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-2335

Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses. NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.

CVSS2: 5
6%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2320

WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.

CVSS2: 7.5
1%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2317

Shorewall 2.4.x before 2.4.1, 2.2.x before 2.2.5, and 2.0.x before 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with an accepted MAC address to bypass other firewall rules or policies.

CVSS2: 7.5
2%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2302

PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion.

CVSS2: 2.1
0%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2301

PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.

CVSS2: 5
3%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2295

NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero datablock size.

CVSS2: 5
5%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2277

Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.

CVSS2: 10
13%
Средний
около 21 года назад
ubuntu логотип
CVE-2005-2270

Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.

CVSS2: 7.5
6%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2269

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

CVSS2: 7.5
6%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2268

Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

CVSS2: 2.6
3%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2267

Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.

CVSS2: 7.5
4%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-2266

Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.

CVSS2: 5
2%
Низкий
около 21 года назад

Уязвимостей на страницу