Show filters
977 Total Results
Displaying 91-100 of 977
Sort by:
Attacker Value
Unknown

CVE-2019-19319

Disclosure Date: November 27, 2019 (last updated November 27, 2024)
In the Linux kernel before 5.2, a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call, aka CID-345c0dbf3a30.
Attacker Value
Unknown

CVE-2011-2717

Disclosure Date: November 27, 2019 (last updated November 27, 2024)
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.
Attacker Value
Unknown

CVE-2019-10216

Disclosure Date: November 27, 2019 (last updated November 08, 2023)
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges and access files outside of restricted areas.
Attacker Value
Unknown

CVE-2011-3632

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Hardlink before 0.1.2 operates on full file system objects path names which can allow a local attacker to use this flaw to conduct symlink attacks.
Attacker Value
Unknown

CVE-2011-3630

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Hardlink before 0.1.2 suffer from multiple stack-based buffer overflow flaws because of the way directory trees with deeply nested directories are processed. A remote attacker could provide a specially-crafted directory tree, and trick the local user into consolidating it, leading to hardlink executable crash, or, potentially arbitrary code execution with the privileges of the user running the hardlink executable.
Attacker Value
Unknown

CVE-2011-3631

Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done in the calculation of the required memory space to be used. A remote attacker could provide a specially-crafted directory tree and trick the local user into consolidating it, leading to hardlink executable crash or potentially arbitrary code execution with user privileges.
Attacker Value
Unknown

CVE-2012-5644

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
libuser has information disclosure when moving user's home directory
Attacker Value
Unknown

CVE-2012-5521

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
Attacker Value
Unknown

CVE-2012-5630

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
Attacker Value
Unknown

CVE-2012-0877

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
PyXML: Hash table collisions CPU usage Denial of Service