Show filters
148 Total Results
Displaying 111-120 of 148
Sort by:
Attacker Value
Unknown
CVE-2004-0983
Disclosure Date: March 01, 2005 (last updated February 22, 2025)
The CGI module in Ruby 1.6 before 1.6.8, and 1.8 before 1.8.2, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certain HTTP request.
0
Attacker Value
Unknown
CVE-2004-0989
Disclosure Date: March 01, 2005 (last updated February 22, 2025)
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.
0
Attacker Value
Unknown
CVE-2004-1002
Disclosure Date: March 01, 2005 (last updated February 22, 2025)
Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.
0
Attacker Value
Unknown
CVE-2004-1007
Disclosure Date: March 01, 2005 (last updated February 22, 2025)
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.
0
Attacker Value
Unknown
CVE-2004-1051
Disclosure Date: March 01, 2005 (last updated February 22, 2025)
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname.
0
Attacker Value
Unknown
CVE-2004-0966
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
0
Attacker Value
Unknown
CVE-2004-0957
Disclosure Date: February 09, 2005 (last updated October 04, 2023)
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
0
Attacker Value
Unknown
CVE-2004-0969
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
0
Attacker Value
Unknown
CVE-2005-0156
Disclosure Date: February 07, 2005 (last updated February 22, 2025)
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
0
Attacker Value
Unknown
CVE-2004-0882
Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.
0