Openpkg

Openpkg

27 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 83.47%
  • Published 27.07.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of...

Exploit
  • EPSS 0.13%
  • Published 05.05.2004 04:00:00
  • Last modified 03.04.2025 01:03:51

Kolab stores OpenLDAP passwords in plaintext in the slapd.conf file, which may be installed world-readable, which allows local users to gain privileges.

  • EPSS 7.25%
  • Published 27.08.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.

Exploit
  • EPSS 13.61%
  • Published 12.05.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.

  • EPSS 20.2%
  • Published 31.03.2003 05:00:00
  • Last modified 03.04.2025 01:03:51

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the us...

  • EPSS 1.78%
  • Published 24.09.2002 04:00:00
  • Last modified 03.04.2025 01:03:51

Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify command line arguments to the MTA (e.g. sendmail) in the 5th argument to mail(), altering MTA behavior and poss...

  • EPSS 2.66%
  • Published 15.03.2002 05:00:00
  • Last modified 03.04.2025 01:03:51

Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.