- EPSS 7.36%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to int...
- EPSS 11.29%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and ...
- EPSS 9.33%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
- EPSS 0.95%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the "chroot barrier" with util-vserver, which allows attackers to access files on the host system that are outside of the...
CVE-2005-4178
- EPSS 1.72%
- Published 12.12.2005 21:03:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code via unspecified inputs that cause insufficient memory to be allocated due to an incorrect expression that does not enforce the proper order of operati...
CVE-2005-3912
- EPSS 12.45%
- Published 30.11.2005 11:03:00
- Last modified 03.04.2025 01:03:51
Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary...
CVE-2005-3847
- EPSS 0.07%
- Published 27.11.2005 00:03:00
- Last modified 03.04.2025 01:03:51
The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is performing ...
CVE-2005-3323
- EPSS 2.3%
- Published 27.10.2005 10:02:00
- Last modified 03.04.2025 01:03:51
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
CVE-2005-3302
- EPSS 4.91%
- Published 24.10.2005 10:02:00
- Last modified 03.04.2025 01:03:51
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
CVE-2005-3274
- EPSS 0.13%
- Published 21.10.2005 01:02:00
- Last modified 03.04.2025 01:03:51
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection tab...