Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2011-0640

Disclosure Date: January 25, 2011 (last updated October 04, 2023)
The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.
0
Attacker Value
Unknown

CVE-2010-4176

Disclosure Date: December 07, 2010 (last updated October 04, 2023)
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
0
Attacker Value
Unknown

CVE-2009-1185

Disclosure Date: April 17, 2009 (last updated October 04, 2023)
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
0
Attacker Value
Unknown

CVE-2009-1186

Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
0
Attacker Value
Unknown

CVE-2008-2266

Disclosure Date: May 16, 2008 (last updated October 04, 2023)
uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.
0
Attacker Value
Unknown

CVE-2004-2265

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact.
0
Attacker Value
Unknown

CVE-2004-0333

Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.
0