Show filters
67 Total Results
Displaying 41-50 of 67
Sort by:
Attacker Value
Unknown
CVE-2004-0949
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the first part of the fragmented packet multiple times.
0
Attacker Value
Unknown
CVE-2004-1071
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-1268
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
0
Attacker Value
Unknown
CVE-2004-1269
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.
0
Attacker Value
Unknown
CVE-2004-0883
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_readX function, (3) sending a certain TRANS2 fragmented packet to the smb_receive_trans2 function, (4) sending a samba packet with a certain header size to the smb_proc_readX_data function, or (5) sending a certain packet based offset for the data in a packet to the smb_receive_trans2 function.
0
Attacker Value
Unknown
CVE-2004-1154
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2004-1070
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2004-1073
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.
0
Attacker Value
Unknown
CVE-2004-0914
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE's content decisions.
0
Attacker Value
Unknown
CVE-2004-1267
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file.
0