Show filters
138 Total Results
Displaying 71-80 of 138
Sort by:
Attacker Value
Unknown
CVE-2009-0846
Disclosure Date: April 09, 2009 (last updated February 09, 2024)
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
0
Attacker Value
Unknown
CVE-2008-3281
Disclosure Date: August 27, 2008 (last updated February 03, 2024)
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
0
Attacker Value
Unknown
CVE-2008-2364
Disclosure Date: June 13, 2008 (last updated October 04, 2023)
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
0
Attacker Value
Unknown
CVE-2008-1767
Disclosure Date: May 23, 2008 (last updated October 04, 2023)
Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.
0
Attacker Value
Unknown
CVE-2006-5752
Disclosure Date: June 27, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified.
0
Attacker Value
Unknown
CVE-2007-1352
Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
0
Attacker Value
Unknown
CVE-2007-1351
Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
0
Attacker Value
Unknown
CVE-2007-1349
Disclosure Date: March 30, 2007 (last updated October 04, 2023)
PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
0
Attacker Value
Unknown
CVE-2007-1285
Disclosure Date: March 06, 2007 (last updated February 03, 2024)
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
0
Attacker Value
Unknown
CVE-2007-0455
Disclosure Date: January 30, 2007 (last updated October 04, 2023)
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.
0