Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2005-1038

больше 21 года назад

crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-1035

больше 21 года назад

Multiple buffer overflows in Pavuk before 0.9.32 have unknown attack vectors and impact.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-10004

12 месяцев назад

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2005-0992

больше 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-0990

больше 21 года назад

unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0989

больше 21 года назад

The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-0988

больше 21 года назад

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.

CVSS2: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2005-0977

больше 21 года назад

The shmem_nopage function in shmem.c for the tmpfs driver in Linux kernel 2.6 does not properly verify the address argument, which allows local users to cause a denial of service (kernel crash) via an invalid address.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0967

больше 21 года назад

Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0966

больше 21 года назад

The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2005-0965

больше 21 года назад

The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0961

больше 21 года назад

Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-0953

больше 21 года назад

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

CVSS2: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2005-0941

больше 21 года назад

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0937

больше 21 года назад

Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mmap or other functions.

CVSS2: 1.2
EPSS: Низкий
ubuntu логотип

CVE-2005-0926

больше 21 года назад

Buffer overflow in Sylpheed before 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attachments with MIME-encoded file names.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0916

больше 21 года назад

AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_queue_init function but exits without running io_queue_release, which causes exit_aio and is_hugepage_only_range to fail.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0913

больше 21 года назад

Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0894

больше 21 года назад

OpenmosixCollector and OpenMosixView in OpenMosixView 1.5 allow local users to overwrite or delete arbitrary files via a symlink attack on (1) temporary files in the openmosixcollector directory or (2) nodes.tmp.

CVSS2: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0893

больше 21 года назад

modes.c in smail 3.2.0.120 implements signal handlers with certain unsafe library calls, which may allow attackers to execute arbitrary code via signal handler race conditions, possibly using xmalloc.

CVSS2: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-1038

crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-1035

Multiple buffer overflows in Pavuk before 0.9.32 have unknown attack vectors and impact.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-10004

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled during graph rendering. This flaw allows attackers to execute commands on the underlying operating system with the privileges of the web server process, potentially compromising system integrity.

CVSS3: 8.8
2%
Низкий
12 месяцев назад
ubuntu логотип
CVE-2005-0992

Cross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web script or HTML via the convcharset parameter.

CVSS2: 4.3
5%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0990

unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0989

The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.

CVSS2: 5
10%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0988

Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.

CVSS2: 3.7
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0977

The shmem_nopage function in shmem.c for the tmpfs driver in Linux kernel 2.6 does not properly verify the address argument, which allows local users to cause a denial of service (kernel crash) via an invalid address.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0967

Gaim 1.2.0 allows remote attackers to cause a denial of service (application crash) via a malformed file transfer request to a Jabber user, which leads to an out-of-bounds read.

CVSS2: 5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0966

The IRC protocol plugin in Gaim 1.2.0, and possibly earlier versions, allows (1) remote attackers to inject arbitrary Gaim markup via irc_msg_kick, irc_msg_mode, irc_msg_part, irc_msg_quit, (2) remote attackers to inject arbitrary Pango markup and pop up empty dialog boxes via irc_msg_invite, or (3) malicious IRC servers to cause a denial of service (application crash) by injecting certain Pango markup into irc_msg_badmode, irc_msg_banned, irc_msg_unknown, irc_msg_nochan functions.

CVSS2: 6.4
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0965

The gaim_markup_strip_html function in Gaim 1.2.0, and possibly earlier versions, allows remote attackers to cause a denial of service (application crash) via a string that contains malformed HTML, which causes an out-of-bounds read.

CVSS2: 5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0961

Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0953

Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.

CVSS2: 3.7
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0941

The StgCompObjStream::Load function in OpenOffice.org OpenOffice 1.1.4 and earlier allocates memory based on 16 bit length values, but process memory using 32 bit values, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a DOC document with certain length values, which leads to a heap-based buffer overflow.

CVSS2: 5.1
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0937

Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mmap or other functions.

CVSS2: 1.2
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0926

Buffer overflow in Sylpheed before 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attachments with MIME-encoded file names.

CVSS2: 5.1
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0916

AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_queue_init function but exits without running io_queue_release, which causes exit_aio and is_hugepage_only_range to fail.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0913

Unknown vulnerability in the regex_replace modifier (modifier.regex_replace.php) in Smarty before 2.6.8 allows attackers to execute arbitrary PHP code.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0894

OpenmosixCollector and OpenMosixView in OpenMosixView 1.5 allow local users to overwrite or delete arbitrary files via a symlink attack on (1) temporary files in the openmosixcollector directory or (2) nodes.tmp.

CVSS2: 3.6
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0893

modes.c in smail 3.2.0.120 implements signal handlers with certain unsafe library calls, which may allow attackers to execute arbitrary code via signal handler race conditions, possibly using xmalloc.

CVSS2: 7.6
2%
Низкий
больше 21 года назад

Уязвимостей на страницу