Show filters
47 Total Results
Displaying 21-30 of 47
Sort by:
Attacker Value
Unknown

CVE-2008-1567

Disclosure Date: March 31, 2008 (last updated February 15, 2024)
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
Attacker Value
Unknown

CVE-2008-0063

Disclosure Date: March 19, 2008 (last updated February 09, 2024)
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
Attacker Value
Unknown

CVE-2007-6427

Disclosure Date: January 18, 2008 (last updated October 04, 2023)
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
0
Attacker Value
Unknown

CVE-2007-5000

Disclosure Date: December 13, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2007-6206

Disclosure Date: December 04, 2007 (last updated October 04, 2023)
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2007-3798

Disclosure Date: July 16, 2007 (last updated January 13, 2024)
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
Attacker Value
Unknown

CVE-2007-2654

Disclosure Date: May 14, 2007 (last updated October 04, 2023)
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
0
Attacker Value
Unknown

CVE-2007-0823

Disclosure Date: February 07, 2007 (last updated October 04, 2023)
xterm on Slackware Linux 10.2 stores information that had been displayed for a different user account using the same xterm process, which might allow local users to bypass file permissions and read other users' files, or obtain other sensitive information, by reading the xterm process memory. NOTE: it could be argued that this is an expected consequence of multiple users sharing the same interactive process, in which case this is not a vulnerability.
0
Attacker Value
Unknown

CVE-2005-3626

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
0
Attacker Value
Unknown

CVE-2005-3625

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
0