CVE-2008-3272
- EPSS 0.06%
- Veröffentlicht 08.08.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain da...
- EPSS 9.7%
- Veröffentlicht 13.06.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service...
CVE-2008-0455
- EPSS 18.09%
- Veröffentlicht 25.01.2008 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated use...
CVE-2008-0456
- EPSS 7.58%
- Veröffentlicht 25.01.2008 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject...
CVE-2007-6283
- EPSS 0.14%
- Veröffentlicht 18.12.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.
CVE-2007-6206
- EPSS 0.08%
- Veröffentlicht 04.12.2007 00:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might ...
CVE-2006-5752
- EPSS 11.55%
- Veröffentlicht 27.06.2007 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML vi...
CVE-2007-3304
- EPSS 0.21%
- Veröffentlicht 20.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a denial of service by modifying the worker_score and process_score arrays to reference an arbitrary process ID, which is sent a SIGUSR1 signal from the m...
CVE-2007-1864
- EPSS 5.57%
- Veröffentlicht 09.05.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the bundled libxmlrpc library in PHP before 4.4.7, and 5.x before 5.2.2, has unknown impact and remote attack vectors.
- EPSS 17.13%
- Veröffentlicht 30.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PerlRun.pm in Apache mod_perl before 1.30, and RegistryCooker.pm in mod_perl 2.x, does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted U...