Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2004-0109

около 22 лет назад

Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2004-0108

больше 22 лет назад

The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2004-0106

больше 22 лет назад

Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2004-0105

больше 22 лет назад

Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0104

больше 22 лет назад

Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2004-0097

больше 22 лет назад

Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2004-0094

больше 22 лет назад

Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0093

больше 22 лет назад

XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0084

больше 22 лет назад

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2004-0083

больше 22 лет назад

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2004-0079

почти 22 года назад

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0077

больше 22 лет назад

The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2004-0075

больше 22 лет назад

The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-0047

больше 22 лет назад

Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2004-0010

больше 22 лет назад

Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2004-0009

больше 22 лет назад

Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0006

больше 22 лет назад

Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-0003

больше 22 лет назад

Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2003-1599

почти 12 лет назад

WordPress 0.7 allows remote execution of commands. / Wp-links / links.all.php. An attacker can inject a url in $ abspath and get remote execution of commands with the privileges of the server web (usually nobody).

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2003-1598

почти 12 лет назад

WordPress 0.7 (b2 cafelog code) allows SQL injection. / Blog.header.php. $ posts not converted to an integer, so we can inject sql in this variable. In MySQL 4.x can use UNION and subselects to obtain privileges.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2004-0109

Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x, allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.

CVSS2: 4.6
1%
Низкий
около 22 лет назад
ubuntu логотип
CVE-2004-0108

The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0106

Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.

CVSS2: 7.2
0%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0105

Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

CVSS2: 7.5
8%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0104

Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

CVSS2: 7.5
26%
Средний
больше 22 лет назад
ubuntu логотип
CVE-2004-0097

Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.

CVSS2: 10
10%
Средний
больше 22 лет назад
ubuntu логотип
CVE-2004-0094

Integer signedness errors in XFree86 4.1.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code when using the GLX extension and Direct Rendering Infrastructure (DRI).

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0093

XFree86 4.1.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an out-of-bounds array index when using the GLX extension and Direct Rendering Infrastructure (DRI).

CVSS2: 7.5
3%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0084

Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.

CVSS2: 10
25%
Средний
больше 22 лет назад
ubuntu логотип
CVE-2004-0083

Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.

CVSS2: 10
21%
Средний
больше 22 лет назад
ubuntu логотип
CVE-2004-0079

The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.

CVSS3: 7.5
10%
Низкий
почти 22 года назад
ubuntu логотип
CVE-2004-0077

The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.

CVSS2: 7.2
2%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0075

The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.

CVSS2: 2.1
0%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0047

Multiple programs in trr19 1.0 do not properly drop privileges before executing a system command, which could allow local users to gain privileges.

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0010

Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.

CVSS2: 7.2
0%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0009

Apache-SSL 1.3.28+1.52 and earlier, with SSLVerifyClient set to 1 or 3 and SSLFakeBasicAuth enabled, allows remote attackers to forge a client certificate by using basic authentication with the "one-line DN" of the target user.

CVSS2: 7.5
1%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0006

Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.

CVSS2: 7.5
8%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-0003

Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."

CVSS2: 4.6
0%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2003-1599

WordPress 0.7 allows remote execution of commands. / Wp-links / links.all.php. An attacker can inject a url in $ abspath and get remote execution of commands with the privileges of the server web (usually nobody).

CVSS2: 7.5
3%
Низкий
почти 12 лет назад
ubuntu логотип
CVE-2003-1598

WordPress 0.7 (b2 cafelog code) allows SQL injection. / Blog.header.php. $ posts not converted to an integer, so we can inject sql in this variable. In MySQL 4.x can use UNION and subselects to obtain privileges.

CVSS2: 7.5
3%
Низкий
почти 12 лет назад

Уязвимостей на страницу