- EPSS 7.36%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to int...
- EPSS 11.29%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and ...
- EPSS 9.33%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
CVE-2005-3631
- EPSS 0.05%
- Published 22.12.2005 11:03:00
- Last modified 03.04.2025 01:03:51
udev does not properly set permissions on certain files in /dev/input, which allows local users to obtain sensitive data that is entered at the console, such as user passwords.
CVE-2005-2100
- EPSS 0.06%
- Published 25.10.2005 17:06:00
- Last modified 03.04.2025 01:03:51
The rw_vm function in usercopy.c in the 4GB split patch for the Linux kernel in Red Hat Enterprise Linux 4 does not perform proper bounds checking, which allows local users to cause a denial of service (crash).
- EPSS 20.8%
- Published 25.10.2005 17:06:00
- Last modified 03.04.2025 01:03:51
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused f...
CVE-2005-0403
- EPSS 0.05%
- Published 01.09.2005 22:03:00
- Last modified 03.04.2025 01:03:51
init_dev in tty_io.c in the Red Hat backport of NPTL to Red Hat Enterprise Linux 3 does not properly clear controlling tty's in multi-threaded applications, which allows local users to cause a denial of service (crash) and possibly gain tty access vi...
- EPSS 4.27%
- Published 05.08.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one...
CVE-2005-1760
- EPSS 0.54%
- Published 13.06.2005 04:00:00
- Last modified 03.04.2025 01:03:51
sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.
CVE-2005-0757
- EPSS 0.06%
- Published 18.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The xattr file system code, as backported in Red Hat Enterprise Linux 3 on 64-bit systems, does not properly handle certain offsets, which allows local users to cause a denial of service (system crash) via certain actions on an ext3 file system with ...