Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2007-1352
Disclosure Date: April 06, 2007 (last updated October 04, 2023)
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
0
Attacker Value
Unknown
CVE-2006-6235
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
0
Attacker Value
Unknown
CVE-2005-3626
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
0
Attacker Value
Unknown
CVE-2005-3625
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
0
Attacker Value
Unknown
CVE-2005-3624
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
0
Attacker Value
Unknown
CVE-2004-0940
Disclosure Date: February 09, 2005 (last updated February 22, 2025)
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
0
Attacker Value
Unknown
CVE-2000-0844
Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
0
Attacker Value
Unknown
CVE-2000-0867
Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
0
Attacker Value
Unknown
CVE-1999-0341
Disclosure Date: January 01, 1998 (last updated February 22, 2025)
Buffer overflow in the Linux mail program "deliver" allows local users to gain root access.
0
Attacker Value
Unknown
CVE-1999-0298
Disclosure Date: February 05, 1997 (last updated February 22, 2025)
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.
0