Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown
CVE-2006-4343
Disclosure Date: September 28, 2006 (last updated October 04, 2023)
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
0
Attacker Value
Unknown
CVE-2006-4095
Disclosure Date: September 06, 2006 (last updated February 16, 2024)
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
0
Attacker Value
Unknown
CVE-2006-4482
Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.
0
Attacker Value
Unknown
CVE-2006-4093
Disclosure Date: August 21, 2006 (last updated October 04, 2023)
Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."
0
Attacker Value
Unknown
CVE-2006-3747
Disclosure Date: July 28, 2006 (last updated October 04, 2023)
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
0
Attacker Value
Unknown
CVE-2006-3378
Disclosure Date: July 06, 2006 (last updated October 04, 2023)
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.
0
Attacker Value
Unknown
CVE-2006-2935
Disclosure Date: July 05, 2006 (last updated October 04, 2023)
The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2006-2661
Disclosure Date: May 30, 2006 (last updated October 04, 2023)
ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
0
Attacker Value
Unknown
CVE-2006-2275
Disclosure Date: May 09, 2006 (last updated February 16, 2024)
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."
0
Attacker Value
Unknown
CVE-2006-1728
Disclosure Date: April 14, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
0