CVE-2008-0456
- EPSS 7.58%
- Veröffentlicht 25.01.2008 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject...
CVE-2007-6283
- EPSS 0.11%
- Veröffentlicht 18.12.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.
CVE-2007-6206
- EPSS 0.08%
- Veröffentlicht 04.12.2007 00:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might ...
CVE-2006-7226
- EPSS 1.53%
- Veröffentlicht 03.12.2007 20:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Perl-Compatible Regular Expression (PCRE) library before 6.7 does not properly calculate the compiled memory allocation for regular expressions that involve a quantified "subpattern containing a named recursion or subroutine reference," which allows ...
CVE-2007-3103
- EPSS 0.08%
- Veröffentlicht 15.07.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file.
CVE-2006-5752
- EPSS 14.88%
- Veröffentlicht 27.06.2007 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...
CVE-2007-0773
- EPSS 0.04%
- Veröffentlicht 26.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel before 2.6.9-42.0.8 in Red Hat 4.4 allows local users to cause a denial of service (kernel OOPS from null dereference) via fput in a 32-bit ioctl on 64-bit x86 systems, an incomplete fix of CVE-2005-3044.1.
CVE-2007-3304
- EPSS 0.09%
- Veröffentlicht 20.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the m...
CVE-2007-1351
- EPSS 7.77%
- Veröffentlicht 06.04.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflo...
CVE-2007-1352
- EPSS 1.38%
- Veröffentlicht 06.04.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.