Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2005-0509

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2005-0508

больше 21 года назад

Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0504

больше 21 года назад

Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0503

больше 21 года назад

uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0490

больше 21 года назад

Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2005-0488

около 21 года назад

Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-0474

больше 21 года назад

SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2005-0473

больше 21 года назад

The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0472

больше 21 года назад

Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0469

больше 21 года назад

Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0468

больше 21 года назад

Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-0467

больше 21 года назад

Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0459

больше 21 года назад

phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0449

больше 21 года назад

The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.

CVSS2: 7.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0448

больше 21 года назад

Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.

CVSS2: 1.2
EPSS: Низкий
ubuntu логотип

CVE-2005-0446

больше 21 года назад

Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-0440

больше 21 года назад

ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0439

больше 21 года назад

Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-0438

больше 21 года назад

awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0437

больше 21 года назад

Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-0509

Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".

CVSS2: 4.3
16%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0508

Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."

CVSS2: 4.6
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0504

Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.

CVSS2: 4.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0503

uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0490

Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.

CVSS3: 8.8
6%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0488

Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.

CVSS2: 5
17%
Средний
около 21 года назад
ubuntu логотип
CVE-2005-0474

SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.

CVSS2: 6.4
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0473

The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.

CVSS2: 5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0472

Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.

CVSS2: 5
5%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0469

Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.

CVSS2: 7.5
9%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0468

Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.

CVSS2: 7.5
27%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0467

Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0459

phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.

CVSS2: 5
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0449

The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.

CVSS2: 7.1
5%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0448

Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.

CVSS2: 1.2
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0446

Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.

CVSS2: 5
41%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0440

ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0439

Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.

CVSS2: 7.5
10%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0438

awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.

CVSS2: 5
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0437

Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.

CVSS2: 7.5
2%
Низкий
больше 21 года назад

Уязвимостей на страницу