Show filters
290 Total Results
Displaying 151-160 of 290
Sort by:
Attacker Value
Unknown

CVE-2004-1307

Disclosure Date: December 21, 2004 (last updated February 22, 2025)
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2004-0230

Disclosure Date: August 18, 2004 (last updated February 22, 2025)
TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.
0
Attacker Value
Unknown

CVE-2004-0657

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Integer overflow in the NTP daemon (NTPd) before 4.0 causes the NTP server to return the wrong date/time offset when a client requests a date/time that is more than 34 years away from the server's time.
0
Attacker Value
Unknown

CVE-2004-0157

Disclosure Date: June 01, 2004 (last updated February 22, 2025)
x11.c in xonix 1.4 and earlier uses the current working directory to find and execute the rmail program, which allows local users to execute arbitrary code by modifying the path to point to a malicious rmail program.
0
Attacker Value
Unknown

CVE-2004-1124

Disclosure Date: January 14, 2004 (last updated February 22, 2025)
Unknown vulnerability in chroot on SCO UnixWare 7.1.1 through 7.1.4 allows local users to escape the chroot jail and conduct unauthorized activities.
0
Attacker Value
Unknown

CVE-2003-0914

Disclosure Date: December 15, 2003 (last updated February 22, 2025)
ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.
0
Attacker Value
Unknown

CVE-2003-0937

Disclosure Date: December 15, 2003 (last updated February 22, 2025)
SCO UnixWare 7.1.1, 7.1.3, and Open UNIX 8.0.0 allows local users to bypass protections for the "as" address space file for a process ID (PID) by obtaining a procfs file descriptor for the file and calling execve() on a setuid or setgid program, which leaves the descriptor open to the user.
0
Attacker Value
Unknown

CVE-2003-0834

Disclosure Date: December 01, 2003 (last updated February 22, 2025)
Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.
0
Attacker Value
Unknown

CVE-2003-0658

Disclosure Date: October 20, 2003 (last updated February 22, 2025)
Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules.
0
Attacker Value
Unknown

CVE-2002-1565

Disclosure Date: June 16, 2003 (last updated February 22, 2025)
Buffer overflow in url_filename function for wget 1.8.1 allows attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a long URL.
0