Show filters
104 Total Results
Displaying 81-90 of 104
Sort by:
Attacker Value
Unknown
CVE-2006-1244
Disclosure Date: March 15, 2006 (last updated February 22, 2025)
Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4) JPXStream.cc, and/or (5) Stream.cc. NOTE: this description is based on Debian advisory DSA 979, which is based on changes that were made after other vulnerabilities such as CVE-2006-0301 and CVE-2005-3624 through CVE-2005-3628 were fixed. Some of these newer fixes appear to be security-relevant, although it is not clear if they fix specific issues or are defensive in nature.
0
Attacker Value
Unknown
CVE-2005-1855
Disclosure Date: August 30, 2005 (last updated February 22, 2025)
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2005-0005
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
0
Attacker Value
Unknown
CVE-2005-0398
Disclosure Date: March 14, 2005 (last updated February 22, 2025)
The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.
0
Attacker Value
Unknown
CVE-2004-1034
Disclosure Date: March 01, 2005 (last updated February 22, 2025)
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.
0
Attacker Value
Unknown
CVE-2004-0960
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
0
Attacker Value
Unknown
CVE-2004-0961
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
0
Attacker Value
Unknown
CVE-2004-0891
Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded copy operation that writes to the wrong buffer.
0
Attacker Value
Unknown
CVE-2004-0991
Disclosure Date: January 11, 2005 (last updated February 22, 2025)
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.
0
Attacker Value
Unknown
CVE-2004-1076
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allow local users to execute arbitrary code via large values in the configuration file.
0