CVE-2006-5051
- EPSS 2.52%
- Veröffentlicht 27.09.2006 23:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.
CVE-2006-4482
- EPSS 3.46%
- Veröffentlicht 31.08.2006 21:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple heap-based buffer overflows in the (1) str_repeat and (2) wordwrap functions in ext/standard/string.c in PHP before 5.1.5, when used on a 64-bit system, have unspecified impact and attack vectors, a different vulnerability than CVE-2006-1990...
CVE-2006-4093
- EPSS 0.06%
- Veröffentlicht 21.08.2006 21:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time."
CVE-2006-3747
- EPSS 92.66%
- Veröffentlicht 28.07.2006 18:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (applica...
CVE-2006-3918
- EPSS 91.37%
- Veröffentlicht 28.07.2006 00:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected ba...
CVE-2006-2935
- EPSS 0.22%
- Veröffentlicht 05.07.2006 18:05:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device ...
- EPSS 10.35%
- Veröffentlicht 30.05.2006 19:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
CVE-2006-2016
- EPSS 21.99%
- Veröffentlicht 25.04.2006 12:50:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d) template...
CVE-2006-1753
- EPSS 0.06%
- Veröffentlicht 18.04.2006 20:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
A cron job in fcheck before 2.7.59 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
CVE-2006-1530
- EPSS 25.32%
- Veröffentlicht 14.04.2006 10:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due ...