Show filters
148 Total Results
Displaying 101-110 of 148
Sort by:
Attacker Value
Unknown

CVE-2005-1111

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
Attacker Value
Unknown

CVE-2005-0080

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.
0
Attacker Value
Unknown

CVE-2005-0988

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
0
Attacker Value
Unknown

CVE-2005-0077

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
0
Attacker Value
Unknown

CVE-2005-0206

Disclosure Date: April 27, 2005 (last updated February 22, 2025)
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
0
Attacker Value
Unknown

CVE-2005-0754

Disclosure Date: April 22, 2005 (last updated February 22, 2025)
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2004-1235

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
0
Attacker Value
Unknown

CVE-2005-0750

Disclosure Date: March 27, 2005 (last updated February 22, 2025)
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
0
Attacker Value
Unknown

CVE-2005-0384

Disclosure Date: March 15, 2005 (last updated February 22, 2025)
Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.
0
Attacker Value
Unknown

CVE-2005-0109

Disclosure Date: March 05, 2005 (last updated February 22, 2025)
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
0