Show filters
139 Total Results
Displaying 11-20 of 139
Sort by:
Attacker Value
Unknown
CVE-2005-2377
Disclosure Date: July 26, 2005 (last updated October 04, 2023)
nss_ldap 181 to versions before 213, as used in Mandrake Corporate Server and Mandrake 10.0, and other operating systems, does not properly handle a SIGPIPE signal when sending a search request to an LDAP directory server, which might allow remote attackers to cause a denial of service (crond and other application crash) if they can cause an LDAP server to become unavailable. NOTE: it is not clear whether this attack scenario is sufficient to include this item in CVE.
0
Attacker Value
Unknown
CVE-2005-1267
Disclosure Date: June 10, 2005 (last updated October 04, 2023)
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.
0
Attacker Value
Unknown
CVE-2005-1379
Disclosure Date: May 03, 2005 (last updated October 04, 2023)
The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2005-0085
Disclosure Date: April 27, 2005 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
0
Attacker Value
Unknown
CVE-2005-0206
Disclosure Date: April 27, 2005 (last updated October 04, 2023)
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
0
Attacker Value
Unknown
CVE-2005-0020
Disclosure Date: April 14, 2005 (last updated October 04, 2023)
Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2005-0003
Disclosure Date: April 14, 2005 (last updated October 04, 2023)
The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.
0
Attacker Value
Unknown
CVE-2004-1235
Disclosure Date: April 14, 2005 (last updated October 04, 2023)
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
0
Attacker Value
Unknown
CVE-2005-0473
Disclosure Date: March 14, 2005 (last updated October 04, 2023)
The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.
0
Attacker Value
Unknown
CVE-2005-0472
Disclosure Date: March 14, 2005 (last updated October 04, 2023)
Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.
0