Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2011-0640
Disclosure Date: January 25, 2011 (last updated October 04, 2023)
The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.
0
Attacker Value
Unknown
CVE-2010-4176
Disclosure Date: December 07, 2010 (last updated October 04, 2023)
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
0
Attacker Value
Unknown
CVE-2009-1185
Disclosure Date: April 17, 2009 (last updated October 04, 2023)
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
0
Attacker Value
Unknown
CVE-2009-1186
Disclosure Date: April 17, 2009 (last updated October 04, 2023)
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
0
Attacker Value
Unknown
CVE-2008-2266
Disclosure Date: May 16, 2008 (last updated October 04, 2023)
uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.
0
Attacker Value
Unknown
CVE-2004-2265
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
UUDeview 0.5.20 and earlier handles temporary files insecurely during decoding, with unknown attack vectors and impact.
0
Attacker Value
Unknown
CVE-2004-0333
Disclosure Date: November 23, 2004 (last updated February 22, 2025)
Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters.
0