Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 843

Количество 75 843

ubuntu логотип

CVE-2004-0452

больше 21 года назад

Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2004-0427

около 22 лет назад

The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0424

около 22 лет назад

Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2004-0421

около 22 лет назад

The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0419

около 22 лет назад

XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0418

около 22 лет назад

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-0417

около 22 лет назад

Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0416

около 22 лет назад

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2004-0415

почти 22 года назад

Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0414

около 22 лет назад

CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-0413

около 22 лет назад

libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-0412

около 22 лет назад

Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0409

около 22 лет назад

Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0408

почти 22 года назад

Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0405

около 22 лет назад

CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0403

около 22 лет назад

Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-0402

около 22 лет назад

Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2004-0401

около 22 лет назад

Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-0400

около 22 лет назад

Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0399

около 22 лет назад

Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2004-0452

Race condition in the rmtree function in the File::Path module in Perl 5.6.1 and 5.8.4 sets read/write permissions for the world, which allows local users to delete arbitrary files and directories, and possibly read files and directories, via a symlink attack.

CVSS2: 2.6
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-0427

The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.

CVSS2: 2.1
0%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0424

Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.

CVSS2: 7.2
1%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0421

The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.

CVSS2: 5
4%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0419

XDM in XFree86 opens a chooserFd TCP socket even when DisplayManager.requestPort is 0, which could allow remote attackers to connect to the port, in violation of the intended restrictions.

CVSS2: 7.5
2%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0418

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.

CVSS2: 10
6%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0417

Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.

CVSS2: 5
3%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0416

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

CVSS2: 10
13%
Средний
около 22 лет назад
ubuntu логотип
CVE-2004-0415

Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.

CVSS2: 2.1
1%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0414

CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.

CVSS2: 10
4%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0413

libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via an integer overflow that leads to a heap-based buffer overflow.

CVSS2: 10
6%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0412

Mailman before 2.1.5 allows remote attackers to obtain user passwords via a crafted email request to the Mailman server.

CVSS2: 5
3%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0409

Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.

CVSS2: 7.5
9%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0408

Buffer overflow in the child_service function in the ident2 ident daemon allows remote attackers to execute arbitrary code.

CVSS2: 7.5
3%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0405

CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.

CVSS2: 5
2%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0403

Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.

CVSS2: 5
3%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0402

Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code.

CVSS2: 4.6
0%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0401

Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions.

CVSS2: 10
2%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0400

Stack-based buffer overflow in Exim 4 before 4.33, when the headers_check_syntax option is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code during the header check.

CVSS2: 7.5
7%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0399

Stack-based buffer overflow in Exim 3.35, and other versions before 4, when the sender_verify option is true, allows remote attackers to cause a denial of service and possibly execute arbitrary code during sender verification.

CVSS2: 7.5
21%
Средний
около 22 лет назад

Уязвимостей на страницу