CVE-2005-3120
- EPSS 30.44%
- Published 17.10.2005 20:06:00
- Last modified 03.04.2025 01:03:51
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
CVE-2005-3181
- EPSS 0.15%
- Published 12.10.2005 13:04:00
- Last modified 03.04.2025 01:03:51
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a m...
CVE-2005-2960
- EPSS 0.07%
- Published 05.10.2005 19:02:00
- Last modified 03.04.2025 01:03:51
cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.
CVE-2005-3106
- EPSS 0.08%
- Published 30.09.2005 10:05:00
- Last modified 03.04.2025 01:03:51
Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just per...
CVE-2005-2557
- EPSS 8.43%
- Published 28.09.2005 21:03:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE...
CVE-2005-3055
- EPSS 0.09%
- Published 26.09.2005 19:03:00
- Last modified 03.04.2025 01:03:51
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer ref...
- EPSS 11.69%
- Published 06.09.2005 23:03:00
- Last modified 03.04.2025 01:03:51
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass inten...
CVE-2005-1855
- EPSS 0.06%
- Published 30.08.2005 11:45:00
- Last modified 03.04.2025 01:03:51
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
- EPSS 5.31%
- Published 23.08.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointe...
CVE-2005-2555
- EPSS 0.09%
- Published 16.08.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.