VYPR

CVEs

31,397 total · page 626 of 628

  • CVE-2006-4997HigOct 10, 2006
    risk 0.52cvss 7.5epss 0.35

    The clip_mkip function in net/atm/clip.c of the ATM subsystem in Linux kernel allows remote attackers to cause a denial of service (panic) via unknown vectors that cause the ATM subsystem to access the memory of socket buffers after they are freed (freed pointer dereference).

  • CVE-2006-5160HigOct 5, 2006
    risk 0.53cvss 8.1epss 0.00

    Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher states that "I have no…

  • CVE-2006-5158HigOct 5, 2006
    risk 0.49cvss 7.5epss 0.04

    The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference) and a deadlock.

  • CVE-2006-5051HigSep 27, 2006
    risk 0.46cvss 8.1epss 0.03

    Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.

  • CVE-2006-5014HigSep 27, 2006
    risk 0.60cvss 8.8epss 0.03

    Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.

  • CVE-2006-4663HigSep 9, 2006
    risk 0.51cvss 7.8epss 0.00

    The source code tar archive of the Linux kernel 2.6.16, 2.6.17.11, and possibly other versions specifies weak permissions (0666 and 0777) for certain files and directories, which might allow local users to insert Trojan horse source code that would be used during the next kernel…

  • CVE-2006-4095HigSep 6, 2006
    risk 0.49cvss 7.5epss 0.05

    BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.

  • CVE-2006-4434HigAug 29, 2006
    risk 0.49cvss 7.5epss 0.07

    Use-after-free vulnerability in Sendmail before 8.13.8 allows remote attackers to cause a denial of service (crash) via a long "header line", which causes a previously freed variable to be referenced. NOTE: the original developer has disputed the severity of this issue, saying…

  • CVE-2006-3730HigJul 21, 2006
    risk 0.67cvss 8.8epss 0.86

    Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory…

  • CVE-2006-2916HigJun 15, 2006
    risk 0.51cvss 7.8epss 0.00

    artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.

  • CVE-2006-2492HigKEVMay 20, 2006
    risk 0.75cvss 8.8epss 0.79

    Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a…

  • CVE-2006-2362HigMay 15, 2006
    risk 0.51cvss 7.3epss 0.06

    Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted…

  • CVE-2006-2275HigMay 9, 2006
    risk 0.49cvss 7.5epss 0.03

    Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive buffer."

  • CVE-2006-1547HigKEVMar 30, 2006
    risk 0.63cvss 7.5epss 0.22

    ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides…

  • CVE-2006-1364HigMar 23, 2006
    risk 0.54cvss 7.5epss 0.24

    Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each of several…

  • CVE-2006-1078HigMar 9, 2006
    risk 0.55cvss 8.4epss 0.00

    Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a…

  • CVE-2005-4860HigDec 31, 2005
    risk 0.51cvss 7.8epss 0.00

    Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PASSFILE password file, which makes it easier for local users to gain privileges by decrypting a password.

  • CVE-2005-4868HigDec 31, 2005
    risk 0.49cvss 7.1epss 0.00

    Shared memory sections and events in IBM DB2 8.1 have default permissions of read and write for the Everyone group, which allows local users to gain unauthorized access, gain sensitive information, such as cleartext passwords, and cause a denial of service.

  • CVE-2005-3803HigNov 24, 2005
    risk 0.49cvss 7.5epss 0.01

    Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information.

  • CVE-2005-3716HigNov 21, 2005
    risk 0.49cvss 7.5epss 0.01

    The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers to obtain sensitive information.

  • CVE-2005-3302HigOct 24, 2005
    risk 0.51cvss 7.3epss 0.06

    Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.

  • CVE-2005-3140HigOct 5, 2005
    risk 0.49cvss 7.5epss 0.00

    Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail messages, which allows remote attackers to obtain the cleartext NIS password hashes.

  • CVE-2005-2946HigSep 16, 2005
    risk 0.49cvss 7.5epss 0.00

    The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.

  • CVE-2005-2801HigSep 6, 2005
    risk 0.49cvss 7.5epss 0.03

    xattr.c in the ext2 and ext3 file system code for Linux kernel 2.6 does not properly compare the name_index fields when sharing xattr blocks, which could prevent default ACLs from being applied.

  • CVE-2005-1920HigJul 26, 2005
    risk 0.49cvss 7.5epss 0.03

    The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.

  • CVE-2005-2281HigJul 18, 2005
    risk 0.49cvss 7.5epss 0.00

    WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords.

  • CVE-2005-2181HigJul 11, 2005
    risk 0.49cvss 7.5epss 0.00

    Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.

  • CVE-2005-2182HigJul 11, 2005
    risk 0.49cvss 7.5epss 0.00

    Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.

  • CVE-2005-2160HigJul 6, 2005
    risk 0.49cvss 7.5epss 0.02

    IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.

  • CVE-2005-0772HigJun 28, 2005
    risk 0.50cvss 7.5epss 0.11

    VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an invalid (non-0) "Error Status"…

  • CVE-2005-1306HigJun 15, 2005
    risk 0.53cvss 7.5epss 0.16

    The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."

  • CVE-2005-1891HigJun 9, 2005
    risk 0.49cvss 7.5epss 0.01

    The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.

  • CVE-2005-1941HigJun 8, 2005
    risk 0.51cvss 7.8epss 0.00

    SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.

  • CVE-2005-1794HigJun 1, 2005
    risk 0.49cvss 7.4epss 0.06

    Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.

  • CVE-2005-1831HigMay 31, 2005
    risk 0.55cvss 8.4epss 0.00

    Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able to replicate this issue,…

  • CVE-2005-1828HigMay 26, 2005
    risk 0.49cvss 7.5epss 0.01

    D-Link DSL-504T stores usernames and passwords in cleartext in the router configuration file, which allows remote attackers to obtain sensitive information.

  • CVE-2005-0490HigMay 2, 2005
    risk 0.57cvss 8.8epss 0.03

    Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the…

  • CVE-2005-0877HigMay 2, 2005
    risk 0.49cvss 7.5epss 0.00

    Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.

  • CVE-2005-0891HigMay 2, 2005
    risk 0.49cvss 7.5epss 0.02

    Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.

  • CVE-2005-1036HigMay 2, 2005
    risk 0.51cvss 7.8epss 0.00

    FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain…

  • CVE-2004-1002HigMar 1, 2005
    risk 0.49cvss 7.5epss 0.02

    Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.

  • CVE-2004-0940HigFeb 9, 2005
    risk 0.54cvss 7.8epss 0.04

    Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.

  • CVE-2004-1842HigDec 31, 2004
    risk 0.60cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php.

  • CVE-2004-2013HigDec 31, 2004
    risk 0.51cvss 7.8epss 0.00

    Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory.

  • CVE-2004-2172HigDec 31, 2004
    risk 0.52cvss 7.5epss 0.06

    EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack.

  • CVE-2004-2339HigDec 31, 2004
    risk 0.55cvss 8.4epss 0.01

    Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been…

  • CVE-2004-2397HigDec 31, 2004
    risk 0.49cvss 7.5epss 0.00

    The web-based Management Console in Blue Coat Security Gateway OS 3.0 through 3.1.3.13 and 3.2.1, when importing a private key, stores the key and its passphrase in plaintext in a log file, which allows attackers to steal digital certificates.

  • CVE-2004-0816HigDec 23, 2004
    risk 0.52cvss 7.5epss 0.07

    Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.

  • CVE-2004-1083HigDec 3, 2004
    risk 0.49cvss 7.5epss 0.02

    Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate…

  • CVE-2004-0079HigNov 23, 2004
    risk 0.49cvss 7.5epss 0.02

    The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.