Show filters
120 Total Results
Displaying 101-110 of 120
Sort by:
Attacker Value
Unknown
CVE-2007-6420
Disclosure Date: January 12, 2008 (last updated April 27, 2024)
Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-0005
Disclosure Date: January 12, 2008 (last updated October 04, 2023)
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
0
Attacker Value
Unknown
CVE-2008-0226
Disclosure Date: January 10, 2008 (last updated October 04, 2023)
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.
0
Attacker Value
Unknown
CVE-2007-4772
Disclosure Date: January 09, 2008 (last updated October 04, 2023)
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.
0
Attacker Value
Unknown
CVE-2007-6353
Disclosure Date: December 20, 2007 (last updated July 20, 2024)
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2007-5000
Disclosure Date: December 13, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2007-6206
Disclosure Date: December 04, 2007 (last updated October 04, 2023)
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2007-4829
Disclosure Date: November 02, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
0
Attacker Value
Unknown
CVE-2007-5365
Disclosure Date: October 11, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller than the minimum IP MTU.
0
Attacker Value
Unknown
CVE-2007-5268
Disclosure Date: October 08, 2007 (last updated October 04, 2023)
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.
0