CVE-2007-5116
- EPSS 11.41%
- Published 07.11.2007 23:46:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters in a regular expression.
- EPSS 34.84%
- Published 01.03.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-...
CVE-2004-0957
- EPSS 0.48%
- Published 09.02.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized...
CVE-2004-0940
- EPSS 3.68%
- Published 09.02.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
- EPSS 68.74%
- Published 27.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory al...
- EPSS 7.16%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.
- EPSS 6.77%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "information disclosure, double-free...
- EPSS 10.25%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment ...
- EPSS 10.25%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index in...
- EPSS 16.62%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015.