- EPSS 17.13%
- Veröffentlicht 30.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted U...
CVE-2007-1285
- EPSS 6.89%
- Veröffentlicht 06.03.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Zend Engine in PHP 4.x before 4.4.7, and 5.x before 5.2.2, allows remote attackers to cause a denial of service (stack exhaustion and PHP crash) via deeply nested arrays, which trigger deep recursion in the variable destruction routines.
- EPSS 12.34%
- Veröffentlicht 20.02.2007 17:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting...
CVE-2006-5753
- EPSS 0.08%
- Veröffentlicht 30.01.2007 19:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in the listxattr system call in Linux kernel, when a "bad inode" is present, allows local users to cause a denial of service (data corruption) and possibly gain privileges via unknown vectors.
CVE-2007-0455
- EPSS 4.93%
- Veröffentlicht 30.01.2007 17:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded...
- EPSS 8.9%
- Veröffentlicht 07.12.2006 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated s...
CVE-2006-5170
- EPSS 3.51%
- Veröffentlicht 10.10.2006 04:06:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the...
CVE-2006-5158
- EPSS 3.26%
- Veröffentlicht 05.10.2006 04:04:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The nlmclnt_mark_reclaim in clntlock.c in NFS lockd in Linux kernel before 2.6.16 allows remote attackers to cause a denial of service (process crash) and deny access to NFS exports via unspecified vectors that trigger a kernel oops (null dereference...
CVE-2006-2933
- EPSS 0.08%
- Veröffentlicht 27.07.2006 22:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
kdesktop_lock in kdebase before 3.1.3-5.11 for KDE in Red Hat Enterprise Linux (RHEL) 3 does not properly terminate, which can prevent the screensaver from activating or prevent users from manually locking the desktop.
CVE-2005-1918
- EPSS 2.06%
- Veröffentlicht 31.12.2005 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probabl...