Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2005-0205

больше 21 года назад

KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0204

больше 21 года назад

Linux kernel before 2.6.9, when running on the AMD64 and Intel EM64T architectures, allows local users to write to privileged IO ports via the OUTS instruction.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0202

больше 21 года назад

Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0201

около 21 года назад

D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0198

больше 21 года назад

A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0194

больше 21 года назад

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2005-0180

больше 21 года назад

Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.

CVSS2: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0179

больше 21 года назад

Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0178

больше 21 года назад

Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.

CVSS2: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2005-0177

больше 21 года назад

nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2005-0176

больше 21 года назад

The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0175

больше 21 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-0174

больше 21 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-0173

больше 21 года назад

squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-0162

больше 21 года назад

Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-0161

больше 21 года назад

Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0160

больше 21 года назад

Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0159

больше 21 года назад

The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0158

больше 21 года назад

Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0157

больше 21 года назад

The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-0205

KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors before executing kppp.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0204

Linux kernel before 2.6.9, when running on the AMD64 and Intel EM64T architectures, allows local users to write to privileged IO ports via the OUTS instruction.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0202

Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.

CVSS2: 5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0201

D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.

CVSS2: 2.1
0%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-0198

A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.

CVSS2: 7.5
5%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0194

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

CVSS2: 10
5%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0180

Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and copy_to_user functions.

CVSS2: 3.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0179

Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0178

Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.

CVSS2: 6.2
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0177

nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.

CVSS2: 7.8
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0176

The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.

CVSS2: 5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0175

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

CVSS2: 5
41%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0174

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

CVSS2: 5
51%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0173

squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.

CVSS2: 7.5
32%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0162

Stack-based buffer overflow in the get_internal_addresses function in the pluto application for Openswan 1.x before 1.0.9, and Openswan 2.x before 2.3.0, when compiled with XAUTH and PAM enabled, allows remote authenticated attackers to execute arbitrary code.

CVSS2: 7.2
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0161

Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0160

Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.

CVSS2: 5.1
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0159

The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0158

Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0157

The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.

CVSS2: 7.5
1%
Низкий
больше 21 года назад

Уязвимостей на страницу