Show filters
111 Total Results
Displaying 91-100 of 111
Sort by:
Attacker Value
Unknown
CVE-2012-2351
Disclosure Date: July 12, 2012 (last updated October 04, 2023)
The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, which allows remote SAML IdP servers to spoof users of other SAML IdP servers by using the same internal username.
0
Attacker Value
Unknown
CVE-2011-1400
Disclosure Date: March 25, 2011 (last updated October 04, 2023)
The default configuration of the shell_escape_commands directive in conf/texmf.d/95NonPath.cnf in the tex-common package before 2.08.1 in Debian GNU/Linux squeeze, Ubuntu 10.10 and 10.04 LTS, and possibly other operating systems lists certain programs, which might allow remote attackers to execute arbitrary code via a crafted TeX document.
0
Attacker Value
Unknown
CVE-2010-0012
Disclosure Date: January 08, 2010 (last updated January 27, 2024)
Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.
0
Attacker Value
Unknown
CVE-2009-3553
Disclosure Date: November 20, 2009 (last updated February 03, 2024)
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2005-0206
Disclosure Date: April 27, 2005 (last updated February 22, 2025)
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
0
Attacker Value
Unknown
CVE-2004-0888
Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
0
Attacker Value
Unknown
CVE-2004-0889
Disclosure Date: January 27, 2005 (last updated February 22, 2025)
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
0
Attacker Value
Unknown
CVE-2004-1076
Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allow local users to execute arbitrary code via large values in the configuration file.
0
Attacker Value
Unknown
CVE-2003-0615
Disclosure Date: August 27, 2003 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.
0
Attacker Value
Unknown
CVE-2001-0738
Disclosure Date: October 18, 2001 (last updated February 22, 2025)
LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes to be placed in log messages.
0