Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown

CVE-2006-0743

Disclosure Date: March 09, 2006 (last updated February 22, 2025)
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
0
Attacker Value
Unknown

CVE-2006-0771

Disclosure Date: February 18, 2006 (last updated February 22, 2025)
Format string vulnerability in PunkBuster 1.180 and earlier, as used by Soldier of Fortune II and possibly other games, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in invalid cvar values, which are not properly handled when the server kicks the player and records the reason.
0
Attacker Value
Unknown

CVE-2006-0705

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 through 5.0.8, (5) SSH Tectia Server 4.3.6 and earlier and 4.4.0, and (6) SSH Shell Server 3.2.9 and earlier, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command.
0
Attacker Value
Unknown

CVE-2006-0200

Disclosure Date: January 13, 2006 (last updated February 22, 2025)
Format string vulnerability in the error-reporting feature in the mysqli extension in PHP 5.1.0 and 5.1.1 might allow remote attackers to execute arbitrary code via format string specifiers in MySQL error messages.
0
Attacker Value
Unknown

CVE-2006-0150

Disclosure Date: January 09, 2006 (last updated February 22, 2025)
Multiple format string vulnerabilities in the auth_ldap_log_reason function in Apache auth_ldap 1.6.0 and earlier allows remote attackers to execute arbitrary code via various vectors, including the username.
0
Attacker Value
Unknown

CVE-2006-0082

Disclosure Date: January 04, 2006 (last updated February 22, 2025)
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick 6.2.3 and other versions, and GraphicsMagick, allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a numeric format string specifier such as %d in the file name, a variant of CVE-2005-0397, and as demonstrated using the convert program.
0
Attacker Value
Unknown

CVE-2005-3656

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Multiple format string vulnerabilities in logging functions in mod_auth_pgsql before 2.0.3, when used for user authentication against a PostgreSQL database, allows remote unauthenticated attackers to execute arbitrary code, as demonstrated via the username.
0
Attacker Value
Unknown

CVE-2005-3154

Disclosure Date: October 05, 2005 (last updated February 22, 2025)
Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.
0
Attacker Value
Unknown

CVE-2005-1394

Disclosure Date: May 03, 2005 (last updated February 22, 2025)
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
0
Attacker Value
Unknown

CVE-2005-1122

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP GET request containing double-encoded format string specifiers (aka "double expansion error").
0