- EPSS 5.56%
- Published 12.01.2008 02:46:00
- Last modified 09.04.2025 00:30:58
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
CVE-2007-0454
- EPSS 4.41%
- Published 06.02.2007 02:28:00
- Last modified 09.04.2025 00:30:58
Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during...
- EPSS 9.33%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
- EPSS 11.29%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and ...
- EPSS 7.36%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to int...
- EPSS 0.74%
- Published 26.07.2005 04:00:00
- Last modified 03.04.2025 01:03:51
nss_ldap 181 to versions before 213, as used in Mandrake Corporate Server and Mandrake 10.0, and other operating systems, does not properly handle a SIGPIPE signal when sending a search request to an LDAP directory server, which might allow remote at...
CVE-2005-0206
- EPSS 6.53%
- Published 27.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
CVE-2005-0085
- EPSS 4.73%
- Published 27.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
CVE-2005-0020
- EPSS 0.08%
- Published 14.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in playmidi before 2.4 allows local users to execute arbitrary code.
CVE-2005-0003
- EPSS 0.08%
- Published 14.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbit...