Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 79 713

Количество 79 713

ubuntu логотип

CVE-2004-1188

больше 21 года назад

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-1187

больше 21 года назад

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2004-1186

больше 21 года назад

Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-1185

больше 21 года назад

Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-1184

больше 21 года назад

The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2004-1183

больше 21 года назад

Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2004-1182

больше 21 года назад

hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-1180

больше 22 лет назад

Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-1179

больше 21 года назад

The debstd script in debmake 3.6.x before 3.6.10 and 3.7.x before 3.7.7 allows local users to overwrite arbitrary files via a symlink attack on temporary directories.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-1177

больше 21 года назад

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2004-1176

больше 21 года назад

Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-1175

больше 21 года назад

fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-1174

больше 21 года назад

direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2004-1171

больше 21 года назад

KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2004-1170

больше 21 года назад

a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2004-1165

больше 21 года назад

Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-1162

больше 21 года назад

The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-1161

больше 21 года назад

rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-1158

больше 21 года назад

Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2004-1156

больше 21 года назад

Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2004-1188

The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3) PROP_TAG, (4) MDPR_TAG, and (5) CONT_TAG values, a different vulnerability than CVE-2004-1187.

CVSS2: 10
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1187

Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.

CVSS2: 10
5%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1186

Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).

CVSS2: 5
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1185

Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1184

The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.

CVSS2: 4.6
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1183

Integer overflow in the tiffdump utility for libtiff 3.7.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted TIFF file.

CVSS2: 5.1
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1182

hfaxd in HylaFAX before 4.2.1, when installed with a "weak" hosts.hfaxd file, allows remote attackers to authenticate and bypass intended access restrictions via a crafted (1) username or (2) hostname that satisfies a regular expression that is matched against a hosts.hfaxd entry without a password.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1180

Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).

CVSS2: 5
2%
Низкий
больше 22 лет назад
ubuntu логотип
CVE-2004-1179

The debstd script in debmake 3.6.x before 3.6.10 and 3.7.x before 3.7.7 allows local users to overwrite arbitrary files via a symlink attack on temporary directories.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1177

Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1176

Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1175

fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1174

direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."

CVSS2: 5
1%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1171

KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB shares.

CVSS2: 2.1
0%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1170

a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

CVSS2: 10
16%
Средний
больше 21 года назад
ubuntu логотип
CVE-2004-1165

Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1162

The unison command in scponly before 4.0 does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via the (1) -rshcmd or (2) -sshcmd flags.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1161

rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.

CVSS2: 7.5
7%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1158

Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2004-1156

Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

CVSS2: 4.3
1%
Низкий
больше 21 года назад

Уязвимостей на страницу