Show filters
45 Total Results
Displaying 21-30 of 45
Sort by:
Attacker Value
Unknown
CVE-2017-15924
Disclosure Date: October 27, 2017 (last updated November 26, 2024)
In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions.
0
Attacker Value
Unknown
CVE-2017-12424
Disclosure Date: August 04, 2017 (last updated November 26, 2024)
In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting environments in which a Control Panel allows an unprivileged user account to create subaccounts.
0
Attacker Value
Unknown
CVE-2016-6252
Disclosure Date: February 17, 2017 (last updated November 26, 2024)
Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.
0
Attacker Value
Unknown
CVE-2011-0721
Disclosure Date: February 19, 2011 (last updated October 04, 2023)
Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.
0
Attacker Value
Unknown
CVE-2008-7011
Disclosure Date: August 19, 2009 (last updated October 04, 2023)
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set.
0
Attacker Value
Unknown
CVE-2009-1329
Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.
0
Attacker Value
Unknown
CVE-2008-6704
Disclosure Date: April 10, 2009 (last updated October 04, 2023)
Integer overflow in the NET_Compressor::Decompress function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server crash) via a crafted packet with a 0xc1 value that contains no compressed data, which triggers a copy of a large amount of memory.
0
Attacker Value
Unknown
CVE-2008-6702
Disclosure Date: April 10, 2009 (last updated October 04, 2023)
S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception.
0
Attacker Value
Unknown
CVE-2008-6703
Disclosure Date: April 10, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decompress function.
0
Attacker Value
Unknown
CVE-2008-6705
Disclosure Date: April 10, 2009 (last updated October 04, 2023)
The MultipacketReciever::RecievePacket function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server termination) via a crafted packet without an expected 0xe0 or 0xe1 value, which triggers the INT3 instruction.
0