Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2005-1315

больше 21 года назад

Cross-site scripting (XSS) vulnerability in Horde Turba module before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-1314

больше 21 года назад

Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-1309

больше 21 года назад

Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-1294

больше 21 года назад

The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-1290

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight parameter to viewtopic.php, or (3) forumname or forumdesc parameters to admin_forums.php.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-1281

больше 21 года назад

Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-1280

больше 21 года назад

The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-1279

больше 21 года назад

tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-1278

больше 21 года назад

The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-1275

больше 21 года назад

Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-1274

больше 21 года назад

Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2005-1269

около 21 года назад

Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-1268

около 21 года назад

Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-1267

около 21 года назад

The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-1266

около 21 года назад

Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-1265

около 21 года назад

The mmap function in the Linux Kernel 2.6.10 can be used to create memory maps with a start address beyond the end address, which allows local users to cause a denial of service (kernel crash).

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-1264

больше 21 года назад

Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-1263

больше 21 года назад

The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-1262

больше 21 года назад

Gaim 1.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed MSN message.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-1261

больше 21 года назад

Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-1315

Cross-site scripting (XSS) vulnerability in Horde Turba module before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1314

Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1309

Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1294

The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.

CVSS2: 7.2
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1290

Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight parameter to viewtopic.php, or (3) forumname or forumdesc parameters to admin_forums.php.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1281

Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

CVSS2: 5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1280

The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

CVSS2: 5
10%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-1279

tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.

CVSS2: 5
19%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-1278

The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.

CVSS2: 5
11%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-1275

Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.

CVSS2: 5
14%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-1274

Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter.

CVSS2: 10
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1269

Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.

CVSS2: 5
2%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-1268

Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.

CVSS2: 5
8%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-1267

The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.

CVSS2: 5
14%
Средний
около 21 года назад
ubuntu логотип
CVE-2005-1266

Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.

CVSS2: 5
8%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-1265

The mmap function in the Linux Kernel 2.6.10 can be used to create memory maps with a start address beyond the end address, which allows local users to cause a denial of service (kernel crash).

CVSS2: 2.1
0%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-1264

Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589.

CVSS2: 7.2
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1263

The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.

CVSS2: 7.2
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1262

Gaim 1.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed MSN message.

CVSS2: 5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1261

Stack-based buffer overflow in the URL parsing function in Gaim before 1.3.0 allows remote attackers to execute arbitrary code via an instant message (IM) with a large URL.

CVSS2: 7.5
12%
Средний
больше 21 года назад

Уязвимостей на страницу