Show filters
977 Total Results
Displaying 91-100 of 977
Sort by:
Attacker Value
Unknown
CVE-2019-19319
Disclosure Date: November 27, 2019 (last updated November 27, 2024)
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, aka CID-345c0dbf3a30.
0
Attacker Value
Unknown
CVE-2011-2717
Disclosure Date: November 27, 2019 (last updated November 27, 2024)
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
0
Attacker Value
Unknown
CVE-2019-10216
Disclosure Date: November 27, 2019 (last updated November 08, 2023)
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
0
Attacker Value
Unknown
CVE-2011-3632
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
0
Attacker Value
Unknown
CVE-2011-3630
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.
0
Attacker Value
Unknown
CVE-2011-3631
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges.
0
Attacker Value
Unknown
CVE-2012-5644
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
libuser has information disclosure when moving user's home directory
0
Attacker Value
Unknown
CVE-2012-5521
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
0
Attacker Value
Unknown
CVE-2012-5630
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
0
Attacker Value
Unknown
CVE-2012-0877
Disclosure Date: November 22, 2019 (last updated November 27, 2024)
PyXML: Hash table collisions CPU usage Denial of Service
0