Show filters
78 Total Results
Displaying 61-70 of 78
Sort by:
Attacker Value
Unknown

CVE-2007-2443

Disclosure Date: June 26, 2007 (last updated October 04, 2023)
Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.
0
Attacker Value
Unknown

CVE-2007-2798

Disclosure Date: June 26, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
0
Attacker Value
Unknown

CVE-2007-2442

Disclosure Date: June 26, 2007 (last updated October 04, 2023)
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.
0
Attacker Value
Unknown

CVE-2007-3304

Disclosure Date: June 20, 2007 (last updated October 04, 2023)
Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1 killer."
0
Attacker Value
Unknown

CVE-2007-2875

Disclosure Date: June 11, 2007 (last updated October 04, 2023)
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading the /dev/cpuset/tasks file.
0
Attacker Value
Unknown

CVE-2007-2728

Disclosure Date: May 16, 2007 (last updated August 17, 2024)
The soap extension in PHP calls php_rand_r with an uninitialized seed variable, which has unknown impact and attack vectors, a related issue to the mcrypt_create_iv issue covered by CVE-2007-2727. Note: The PHP team argue that this is not a valid security issue.
0
Attacker Value
Unknown

CVE-2007-2691

Disclosure Date: May 16, 2007 (last updated October 04, 2023)
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
0
Attacker Value
Unknown

CVE-2007-2444

Disclosure Date: May 14, 2007 (last updated October 04, 2023)
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to the root user.
0
Attacker Value
Unknown

CVE-2007-2583

Disclosure Date: May 10, 2007 (last updated October 04, 2023)
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-dependent attackers to cause a denial of service (crash) via a crafted IF clause that results in a divide-by-zero error and a NULL pointer dereference.
0
Attacker Value
Unknown

CVE-2007-1864

Disclosure Date: May 09, 2007 (last updated October 04, 2023)
Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
0