CVE-2007-3387
- EPSS 11.4%
- Veröffentlicht 30.07.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute...
CVE-2007-3798
- EPSS 72.12%
- Veröffentlicht 16.07.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
- EPSS 39.32%
- Veröffentlicht 26.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cl...
CVE-2007-2443
- EPSS 25.36%
- Veröffentlicht 26.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.
- EPSS 14.89%
- Veröffentlicht 26.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
CVE-2007-3409
- EPSS 12.39%
- Veröffentlicht 26.06.2007 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop.
CVE-2007-2833
- EPSS 1.34%
- Veröffentlicht 21.06.2007 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.
CVE-2007-3278
- EPSS 0.58%
- Veröffentlicht 19.06.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host param...
CVE-2007-2875
- EPSS 0.06%
- Veröffentlicht 11.06.2007 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading th...
CVE-2007-2691
- EPSS 1.04%
- Veröffentlicht 16.05.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.