Количество 77 202
Количество 77 202
CVE-2003-0001
CVE-2002-2443
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.
CVE-2002-2439
operator new[] sometimes returns pointers to heap blocks which are too small. When a new array is allocated, the C++ run-time has to calculate its size. The product may exceed the maximum value which can be stored in a machine register. This error is ignored, and the truncated value is used for the heap allocation. This may lead to heap overflows and therefore security bugs. (See http://cert.uni-stuttgart.de/advisories/calloc.php for further references.)
CVE-2002-2438
firewalls might let some TCP flags combinations pass (e.g. all with RST flag set) and the OS (e.g. Linux) stack would in turn accept a TCP session it might not have accepted otherwise.
CVE-2002-1581
CVE-2002-1341
CVE-2002-1165
CVE-2002-1157
CVE-2002-0843
CVE-2002-0840
CVE-2002-0839
CVE-2002-0662
CVE-2002-0435
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system.
CVE-2002-0399
CVE-2002-0389
CVE-2002-0379
CVE-2001-1593
Jakub Wilk found that a2ps, a tool to convert text and other types of files to PostScript, insecurely used a temporary file in spy_user(). A local attacker could use this flaw to perform a symbolic link attack to modify an arbitrary file accessible to the user running a2ps.
CVE-2001-1535
CVE-2001-1413
CVE-2001-0775
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS2: 5 | 70% Высокий | больше 23 лет назад | ||
CVE-2002-2443 schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103. | CVSS2: 5 | 6% Низкий | больше 13 лет назад | |
CVE-2002-2439 operator new[] sometimes returns pointers to heap blocks which are too small. When a new array is allocated, the C++ run-time has to calculate its size. The product may exceed the maximum value which can be stored in a machine register. This error is ignored, and the truncated value is used for the heap allocation. This may lead to heap overflows and therefore security bugs. (See http://cert.uni-stuttgart.de/advisories/calloc.php for further references.) | CVSS3: 7.8 | 1% Низкий | почти 7 лет назад | |
CVE-2002-2438 firewalls might let some TCP flags combinations pass (e.g. all with RST flag set) and the OS (e.g. Linux) stack would in turn accept a TCP session it might not have accepted otherwise. | CVSS3: 7.5 | 4% Низкий | больше 5 лет назад | |
CVSS2: 5 | 8% Низкий | больше 21 года назад | ||
CVSS2: 6.8 | 2% Низкий | больше 23 лет назад | ||
CVSS2: 4.6 | 1% Низкий | почти 24 года назад | ||
CVSS2: 7.5 | 10% Низкий | почти 24 года назад | ||
CVSS2: 7.5 | 21% Средний | почти 24 года назад | ||
CVSS2: 6.8 | 95% Критический | почти 24 года назад | ||
CVSS2: 7.2 | 1% Низкий | почти 24 года назад | ||
CVSS2: 2.1 | 0% Низкий | почти 24 года назад | ||
CVE-2002-0435 Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".." directory that is higher than expected, possibly up to the root file system. | CVSS2: 1.2 | 0% Низкий | около 24 лет назад | |
CVSS2: 5 | 4% Низкий | почти 24 года назад | ||
CVSS2: 2.1 | 0% Низкий | около 24 лет назад | ||
CVSS2: 7.5 | 19% Средний | около 24 лет назад | ||
CVE-2001-1593 Jakub Wilk found that a2ps, a tool to convert text and other types of files to PostScript, insecurely used a temporary file in spy_user(). A local attacker could use this flaw to perform a symbolic link attack to modify an arbitrary file accessible to the user running a2ps. | CVSS2: 2.1 | 0% Низкий | больше 12 лет назад | |
CVSS2: 4.6 | 0% Низкий | больше 24 лет назад | ||
CVSS2: 7.5 | 5% Низкий | больше 21 года назад | ||
CVSS2: 7.5 | 16% Средний | почти 25 лет назад |
Уязвимостей на страницу