Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown
CVE-2013-4425
Disclosure Date: November 18, 2013 (last updated October 05, 2023)
The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key.
0
Attacker Value
Unknown
CVE-2005-0465
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.
0
Attacker Value
Unknown
CVE-2004-0135
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory.
0
Attacker Value
Unknown
CVE-2003-0688
Disclosure Date: October 20, 2003 (last updated February 22, 2025)
The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.
0
Attacker Value
Unknown
CVE-2003-0694
Disclosure Date: October 06, 2003 (last updated February 22, 2025)
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
0
Attacker Value
Unknown
CVE-2003-0028
Disclosure Date: March 25, 2003 (last updated February 22, 2025)
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
0
Attacker Value
Unknown
CVE-2003-0064
Disclosure Date: March 03, 2003 (last updated February 22, 2025)
The dtterm terminal emulator allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2002-1323
Disclosure Date: December 11, 2002 (last updated February 22, 2025)
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.
0
Attacker Value
Unknown
CVE-2002-0678
Disclosure Date: July 23, 2002 (last updated February 22, 2025)
CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.
0
Attacker Value
Unknown
CVE-2002-0677
Disclosure Date: July 23, 2002 (last updated February 22, 2025)
CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.
0