Show filters
322 Total Results
Displaying 271-280 of 322
Sort by:
Attacker Value
Unknown

CVE-2009-2408

Disclosure Date: July 30, 2009 (last updated February 15, 2024)
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.
Attacker Value
Unknown

CVE-2009-0949

Disclosure Date: June 09, 2009 (last updated February 09, 2024)
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.
Attacker Value
Unknown

CVE-2009-0040

Disclosure Date: February 22, 2009 (last updated February 09, 2024)
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.
0
Attacker Value
Unknown

CVE-2008-4989

Disclosure Date: November 13, 2008 (last updated February 09, 2024)
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
Attacker Value
Unknown

CVE-2008-2931

Disclosure Date: July 09, 2008 (last updated October 04, 2023)
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the properties of a mountpoint.
Attacker Value
Unknown

CVE-2007-4394

Disclosure Date: August 17, 2007 (last updated October 04, 2023)
Unspecified vulnerability in a "core clean" cron job created by the findutils-locate package on SUSE Linux 10.0 and 10.1 and Enterprise Server 9 and 10 before 20070810 allows local users to delete of arbitrary files via unknown vectors.
0
Attacker Value
Unknown

CVE-2007-1285

Disclosure Date: March 06, 2007 (last updated February 03, 2024)
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
Attacker Value
Unknown

CVE-2006-5616

Disclosure Date: October 31, 2006 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2006-2658

Disclosure Date: September 12, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request.
0
Attacker Value
Unknown

CVE-2006-0745

Disclosure Date: March 21, 2006 (last updated February 22, 2025)
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.
0