CVE-2005-0988
- EPSS 0.12%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip af...
CVE-2005-1038
- EPSS 0.08%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2...
- EPSS 5.67%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwa...
CVE-2005-0087
- EPSS 0.1%
- Veröffentlicht 27.04.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.
CVE-2005-0206
- EPSS 6.53%
- Veröffentlicht 27.04.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
CVE-2004-0812
- EPSS 0.07%
- Veröffentlicht 14.04.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unknown vulnerability in the Linux kernel before 2.4.23, on the AMD AMD64 and Intel EM64T architectures, associated with "setting up TSS limits," allows local users to cause a denial of service (crash) and possibly execute arbitrary code.
CVE-2004-1004
- EPSS 0.95%
- Veröffentlicht 14.04.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
CVE-2004-1005
- EPSS 1.11%
- Veröffentlicht 14.04.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
- EPSS 1.29%
- Veröffentlicht 14.04.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
- EPSS 1.06%
- Veröffentlicht 14.04.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."