- EPSS 37.59%
- Veröffentlicht 06.04.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The telnet daemon (telnetd) in MIT krb5 before 1.6.1 allows remote attackers to bypass authentication and gain system access via a username beginning with a '-' character, a similar issue to CVE-2007-0882.
- EPSS 13.22%
- Veröffentlicht 06.04.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the krb5_klog_syslog function in the kadm5 library, as used by the Kerberos administration daemon (kadmind) and Key Distribution Center (KDC), in MIT krb5 before 1.6.1 allows remote authenticated users to execute arbitr...
- EPSS 11.52%
- Veröffentlicht 06.04.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Double free vulnerability in the GSS-API library (lib/gssapi/krb5/k5unseal.c), as used by the Kerberos administration daemon (kadmind) in MIT krb5 before 1.6.1, when used with the authentication method provided by the RPCSEC_GSS RPC library, allows r...
CVE-2007-1887
- EPSS 3.11%
- Veröffentlicht 06.04.2007 01:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in the sqlite_decode_binary function in the bundled sqlite library in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 allows context-dependent attackers to execute arbitrary code via an empty value of the in parameter, as demonstrated by ca...
CVE-2007-1667
- EPSS 1.99%
- Veröffentlicht 24.03.2007 21:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagick, allow user-assisted remote attackers to cause a denial of service (crash) or obtain sensitive inf...
CVE-2007-0994
- EPSS 2.5%
- Veröffentlicht 06.03.2007 00:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI...
CVE-2007-0009
- EPSS 48.68%
- Veröffentlicht 26.02.2007 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System ser...
CVE-2007-0778
- EPSS 1.04%
- Veröffentlicht 26.02.2007 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive i...
CVE-2007-0897
- EPSS 5.27%
- Veröffentlicht 16.02.2007 19:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed scans) via CAB archives with a cabinet header record l...
CVE-2007-0454
- EPSS 4.41%
- Veröffentlicht 06.02.2007 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during...