Show filters
215 Total Results
Displaying 151-160 of 215
Sort by:
Attacker Value
Unknown
CVE-2005-3630
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.
0
Attacker Value
Unknown
CVE-2005-2970
Disclosure Date: October 25, 2005 (last updated February 22, 2025)
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.
0
Attacker Value
Unknown
CVE-2005-1267
Disclosure Date: June 10, 2005 (last updated February 22, 2025)
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.
0
Attacker Value
Unknown
CVE-2005-0085
Disclosure Date: April 27, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
0
Attacker Value
Unknown
CVE-2005-0206
Disclosure Date: April 27, 2005 (last updated February 22, 2025)
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
0
Attacker Value
Unknown
CVE-2005-0754
Disclosure Date: April 22, 2005 (last updated February 22, 2025)
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-1235
Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
0
Attacker Value
Unknown
CVE-2005-0750
Disclosure Date: March 27, 2005 (last updated February 22, 2025)
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
0
Attacker Value
Unknown
CVE-2005-0736
Disclosure Date: March 09, 2005 (last updated February 22, 2025)
Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.
0
Attacker Value
Unknown
CVE-2005-0667
Disclosure Date: March 07, 2005 (last updated February 22, 2025)
Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.
0