Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 713

Количество 79 713

ubuntu логотип

CVE-2005-0064

больше 21 года назад

Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0039

больше 21 года назад

Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2005-0038

больше 20 лет назад

The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0034

больше 21 года назад

An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2005-0033

больше 21 года назад

Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2005-0023

почти 21 год назад

gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0022

больше 21 года назад

Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0021

больше 21 года назад

Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-0020

больше 21 года назад

Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-0019

больше 21 года назад

Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0018

больше 21 года назад

The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0017

больше 21 года назад

The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0016

больше 21 года назад

Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary code.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-0015

больше 21 года назад

diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0014

больше 21 года назад

Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0013

больше 21 года назад

nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2005-0012

больше 21 года назад

Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0011

больше 21 года назад

Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2005-0010

больше 21 года назад

Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0009

больше 21 года назад

Unknown vulnerability in the Gnutella dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash).

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2005-0064

Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.

CVSS2: 7.5
7%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0039

Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause plaintext data from the inner packet to be returned in ICMP messages, as demonstrated using bit-flipping attacks and (1) Destination Address Rewriting, (2) a modified header length that causes portions of the packet to be interpreted as IP Options, or (3) a modified protocol field and source address.

CVSS2: 6.4
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0038

The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.

CVSS2: 5
6%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-0034

An "incorrect assumption" in the authvalidated validator function in BIND 9.3.0, when DNSSEC is enabled, allows remote attackers to cause a denial of service (named server exit) via crafted DNS packets that cause an internal consistency test (self-check) to fail.

CVSS2: 4.3
6%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0033

Buffer overflow in the code for recursion and glue fetching in BIND 8.4.4 and 8.4.5 allows remote attackers to cause a denial of service (crash) via queries that trigger the overflow in the q_usedns array that tracks nameservers and addresses.

CVSS2: 5
11%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0023

gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed.

CVSS2: 2.1
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-0022

Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.

CVSS2: 4.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0021

Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.

CVSS2: 7.2
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0020

Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.

CVSS2: 7.2
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0019

Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0018

The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0017

The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0016

Buffer overflow in the exported_display function in xatitv in gatos before 0.0.5 allows local users to execute arbitrary code.

CVSS2: 7.2
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0015

diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0014

Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0013

nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.

CVSS2: 7.2
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0012

Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0011

Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.

CVSS2: 10
5%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0010

Unknown vulnerability in the MMSE dissector in Ethereal 0.10.4 through 0.10.8 allows remote attackers to cause a denial of service by triggering a free of statically allocated memory.

CVSS2: 5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0009

Unknown vulnerability in the Gnutella dissector in Ethereal 0.10.6 through 0.10.8 allows remote attackers to cause a denial of service (application crash).

CVSS2: 5
2%
Низкий
больше 21 года назад

Уязвимостей на страницу