- EPSS 15.59%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
CVE-2004-1190
- EPSS 0.09%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
SUSE Linux before 9.1 and SUSE Linux Enterprise Server before 9 do not properly check commands sent to CD devices that have been opened read-only, which could allow local users to conduct unauthorized write activities to modify the firmware of associ...
CVE-2004-1191
- EPSS 0.06%
- Published 10.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Race condition in SuSE Linux 8.1 through 9.2, when run on SMP systems that have more than 4GB of memory, could allow local users to read unauthorized memory from "foreign memory pages."
- EPSS 0.74%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
The tcp_find_option function of the netfilter subsystem for IPv6 in the SUSE Linux 2.6.5 kernel with USAGI patches, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via...
CVE-2004-0802
- EPSS 6.29%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
CVE-2004-0817
- EPSS 3.6%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.
CVE-2004-1476
- EPSS 2.05%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Stack-based buffer overflow in the VideoCD (VCD) code in xine-lib 1-rc2 through 1-rc5, as derived from libcdio, allows attackers to execute arbitrary code via a VideoCD with an unterminated disk label.
- EPSS 25.86%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.
CVE-2004-1895
- EPSS 0.08%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.
CVE-2004-2097
- EPSS 0.09%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Multiple scripts on SuSE Linux 9.0 allow local users to overwrite arbitrary files via a symlink attack on (1) /tmp/fvwm-bug created by fvwm-bug, (2) /tmp/wmmenu created by wm-oldmenu2new, (3) /tmp/rates created by x11perfcomp, (4) /tmp/xf86debug.1.lo...