Show filters
172 Total Results
Displaying 161-170 of 172
Sort by:
Attacker Value
Unknown

CVE-2009-0068

Disclosure Date: January 07, 2009 (last updated October 04, 2023)
Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.
0
Attacker Value
Unknown

CVE-2008-4311

Disclosure Date: December 10, 2008 (last updated October 04, 2023)
The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.
0
Attacker Value
Unknown

CVE-2008-4984

Disclosure Date: November 06, 2008 (last updated October 04, 2023)
scratchbox2 1.99.0.24 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/dpkg.#####.tmp, (b) /tmp/missing_deps.#####, and (c) /tmp/sb2-pkg-chk.$tstamp.##### temporary files, related to the (1) dpkg-checkbuilddeps and (2) sb2-check-pkg-mappings scripts.
0
Attacker Value
Unknown

CVE-2008-3834

Disclosure Date: October 07, 2008 (last updated October 04, 2023)
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
0
Attacker Value
Unknown

CVE-2008-1803

Disclosure Date: May 12, 2008 (last updated October 04, 2023)
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.
0
Attacker Value
Unknown

CVE-2008-1802

Disclosure Date: May 12, 2008 (last updated October 04, 2023)
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitrary code via a Remote Desktop Protocol (RDP) redirect request with modified length fields.
0
Attacker Value
Unknown

CVE-2008-1801

Disclosure Date: May 12, 2008 (last updated October 04, 2023)
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.
0
Attacker Value
Unknown

CVE-2008-1658

Disclosure Date: April 11, 2008 (last updated October 04, 2023)
Format string vulnerability in the grant helper (polkit-grant-helper.c) in PolicyKit 0.7 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in a password.
0
Attacker Value
Unknown

CVE-2008-0595

Disclosure Date: February 29, 2008 (last updated February 01, 2024)
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.
0
Attacker Value
Unknown

CVE-2007-5388

Disclosure Date: October 12, 2007 (last updated October 04, 2023)
Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) app parameter to apps/apps.php and the (2) wsk parameter to wsk/wsk.php.
0