Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2005-0156

больше 21 года назад

Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0155

больше 21 года назад

The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0152

больше 21 года назад

PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0150

больше 21 года назад

Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0149

больше 21 года назад

Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0147

больше 21 года назад

Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0146

больше 21 года назад

Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0145

больше 21 года назад

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0144

больше 21 года назад

Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0143

больше 21 года назад

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0142

больше 21 года назад

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0141

больше 21 года назад

Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0137

больше 21 года назад

Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a "missing Itanium syscall table entry."

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0136

больше 20 лет назад

The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0135

больше 21 года назад

The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0133

больше 21 года назад

ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0131

больше 21 года назад

The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0130

больше 21 года назад

Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0129

больше 21 года назад

The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-0117

больше 21 года назад

Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.

CVSS2: 4.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-0156

Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0155

The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.

CVSS2: 4.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0152

PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."

CVSS2: 7.5
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0150

Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.

CVSS2: 5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0149

Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail messages.

CVSS2: 5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0147

Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0146

Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.

CVSS2: 5
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0145

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

CVSS2: 2.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0144

Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.

CVSS2: 2.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0143

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

CVSS2: 2.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0142

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0141

Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.

CVSS2: 2.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0137

Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a "missing Itanium syscall table entry."

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0136

The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-0135

The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0133

ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.

CVSS2: 5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0131

The Quick Connection dialog in Konversation 0.15 inadvertently uses the user-provided password as the nickname instead of the user-provided nickname when connecting to the IRC server, which could leak the password to other users.

CVSS2: 5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0130

Certain Perl scripts in Konversation 0.15 allow remote attackers to execute arbitrary commands via shell metacharacters in (1) channel names or (2) song names that are not properly quoted when the user runs IRC scripts.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0129

The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.

CVSS2: 7.5
10%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0117

Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.

CVSS2: 4.6
0%
Низкий
больше 21 года назад

Уязвимостей на страницу