Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown

CVE-2006-4343

Disclosure Date: September 28, 2006 (last updated October 04, 2023)
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
0
Attacker Value
Unknown

CVE-2006-4095

Disclosure Date: September 06, 2006 (last updated February 16, 2024)
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Attacker Value
Unknown

CVE-2006-4482

Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990.
0
Attacker Value
Unknown

CVE-2006-4093

Disclosure Date: August 21, 2006 (last updated October 04, 2023)
Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."
0
Attacker Value
Unknown

CVE-2006-3747

Disclosure Date: July 28, 2006 (last updated October 04, 2023)
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.
0
Attacker Value
Unknown

CVE-2006-3378

Disclosure Date: July 06, 2006 (last updated October 04, 2023)
passwd command in shadow in Ubuntu 5.04 through 6.06 LTS, when called with the -f, -g, or -s flag, does not check the return code of a setuid call, which might allow local users to gain root privileges if setuid fails in cases such as PAM failures or resource limits.
0
Attacker Value
Unknown

CVE-2006-2935

Disclosure Date: July 05, 2006 (last updated October 04, 2023)
The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that triggers a buffer overflow.
0
Attacker Value
Unknown

CVE-2006-2661

Disclosure Date: May 30, 2006 (last updated October 04, 2023)
ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
0
Attacker Value
Unknown

CVE-2006-2275

Disclosure Date: May 09, 2006 (last updated February 16, 2024)
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."
Attacker Value
Unknown

CVE-2006-1728

Disclosure Date: April 14, 2006 (last updated October 04, 2023)
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
0