CVE-2007-3798
- EPSS 72.69%
- Veröffentlicht 16.07.2007 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
- EPSS 42.57%
- Veröffentlicht 26.06.2007 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cl...
CVE-2007-2443
- EPSS 32.35%
- Veröffentlicht 26.06.2007 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.
- EPSS 34.89%
- Veröffentlicht 26.06.2007 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
CVE-2007-3409
- EPSS 18.03%
- Veröffentlicht 26.06.2007 18:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop.
CVE-2007-2833
- EPSS 1.39%
- Veröffentlicht 21.06.2007 20:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.
CVE-2007-3278
- EPSS 0.64%
- Veröffentlicht 19.06.2007 21:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows remote attackers to access arbitrary accounts and execute arbitrary SQL queries via a dblink host param...
CVE-2007-2875
- EPSS 0.1%
- Veröffentlicht 11.06.2007 22:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer underflow in the cpuset_tasks_read function in the Linux kernel before 2.6.20.13, and 2.6.21.x before 2.6.21.4, when the cpuset filesystem is mounted, allows local users to obtain kernel memory contents by using a large offset when reading th...
CVE-2007-2691
- EPSS 1.34%
- Veröffentlicht 16.05.2007 01:19:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
MySQL before 4.1.23, 5.0.x before 5.0.42, and 5.1.x before 5.1.18 does not require the DROP privilege for RENAME TABLE statements, which allows remote authenticated users to rename arbitrary tables.
CVE-2007-2444
- EPSS 1.05%
- Veröffentlicht 14.05.2007 21:19:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to transition to ...