Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown
CVE-2005-3106
Disclosure Date: September 30, 2005 (last updated February 22, 2025)
Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.
0
Attacker Value
Unknown
CVE-2005-2946
Disclosure Date: September 16, 2005 (last updated February 22, 2025)
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.
0
Attacker Value
Unknown
CVE-2005-2492
Disclosure Date: September 14, 2005 (last updated February 22, 2025)
The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.
0
Attacker Value
Unknown
CVE-2005-2700
Disclosure Date: September 06, 2005 (last updated October 04, 2023)
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.
0
Attacker Value
Unknown
CVE-2005-1527
Disclosure Date: August 15, 2005 (last updated February 22, 2025)
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call.
0
Attacker Value
Unknown
CVE-2005-1260
Disclosure Date: May 19, 2005 (last updated February 22, 2025)
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
0
Attacker Value
Unknown
CVE-2005-0758
Disclosure Date: May 13, 2005 (last updated February 22, 2025)
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
0
Attacker Value
Unknown
CVE-2005-0106
Disclosure Date: May 03, 2005 (last updated February 22, 2025)
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.
0
Attacker Value
Unknown
CVE-2005-1111
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
0
Attacker Value
Unknown
CVE-2005-0988
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
0