CVE-2008-0595
- EPSS 0.05%
- Published 29.02.2008 19:44:00
- Last modified 09.04.2025 00:30:58
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a m...
- EPSS 5.56%
- Published 12.01.2008 02:46:00
- Last modified 09.04.2025 00:30:58
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
CVE-2007-0454
- EPSS 4.41%
- Published 06.02.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during...
CVE-2006-0745
- EPSS 0.18%
- Published 21.03.2006 02:06:00
- Last modified 03.04.2025 01:03:51
X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute ar...
- EPSS 7.36%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to int...
- EPSS 11.29%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and ...
- EPSS 9.33%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
- EPSS 0.74%
- Published 26.07.2005 04:00:00
- Last modified 03.04.2025 01:03:51
nss_ldap 181 to versions before 213, as used in Mandrake Corporate Server and Mandrake 10.0, and other operating systems, does not properly handle a SIGPIPE signal when sending a search request to an LDAP directory server, which might allow remote at...
- EPSS 11.27%
- Published 10.06.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.
CVE-2005-0085
- EPSS 4.73%
- Published 27.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.