Show filters
78 Total Results
Displaying 51-60 of 78
Sort by:
Attacker Value
Unknown
CVE-2007-2834
Disclosure Date: September 18, 2007 (last updated October 04, 2023)
Integer overflow in the TIFF parser in OpenOffice.org (OOo) before 2.3; and Sun StarOffice 6, 7, and 8 Office Suite (StarSuite); allows remote attackers to execute arbitrary code via a TIFF file with crafted values of unspecified length fields, which triggers allocation of an incorrect amount of memory, resulting in a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2007-4476
Disclosure Date: September 05, 2007 (last updated October 04, 2023)
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
0
Attacker Value
Unknown
CVE-2007-4657
Disclosure Date: September 04, 2007 (last updated October 04, 2023)
Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.
0
Attacker Value
Unknown
CVE-2007-3998
Disclosure Date: September 04, 2007 (last updated October 04, 2023)
The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set.
0
Attacker Value
Unknown
CVE-2007-4601
Disclosure Date: August 30, 2007 (last updated October 04, 2023)
A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses libwrap but does not specify server connection information.
0
Attacker Value
Unknown
CVE-2007-3847
Disclosure Date: August 23, 2007 (last updated October 04, 2023)
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
0
Attacker Value
Unknown
CVE-2007-3387
Disclosure Date: July 30, 2007 (last updated October 04, 2023)
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based buffer overflow in the StreamPredictor::getNextLine function.
0
Attacker Value
Unknown
CVE-2007-3798
Disclosure Date: July 16, 2007 (last updated January 13, 2024)
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
0
Attacker Value
Unknown
CVE-2007-2949
Disclosure Date: July 04, 2007 (last updated October 04, 2023)
Integer overflow in the seek_to_and_unpack_pixeldata function in the psd.c plugin in Gimp 2.2.15 allows remote attackers to execute arbitrary code via a crafted PSD file that contains a large (1) width or (2) height value.
0
Attacker Value
Unknown
CVE-2006-5752
Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
0