CVE-2007-4476
- EPSS 14.9%
- Veröffentlicht 05.09.2007 01:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:10
Buffer overflow in the safer_name_suffix function in GNU tar has unspecified attack vectors and impact, resulting in a "crashing stack."
CVE-2007-4657
- EPSS 2.99%
- Veröffentlicht 04.09.2007 22:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:31
Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn func...
- EPSS 2.99%
- Veröffentlicht 04.09.2007 18:17:00
- Zuletzt bearbeitet 16.06.2026 22:43:12
The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certai...
CVE-2007-3387
- EPSS 8.57%
- Veröffentlicht 30.07.2007 23:17:00
- Zuletzt bearbeitet 16.06.2026 22:41:54
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute...
CVE-2007-3798
- EPSS 70.39%
- Veröffentlicht 16.07.2007 22:30:00
- Zuletzt bearbeitet 16.06.2026 22:42:45
Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value.
- EPSS 11.38%
- Veröffentlicht 26.06.2007 22:30:00
- Zuletzt bearbeitet 16.06.2026 22:39:35
The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cl...
CVE-2007-2443
- EPSS 3.48%
- Veröffentlicht 26.06.2007 22:30:00
- Zuletzt bearbeitet 16.06.2026 22:39:35
Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.
- EPSS 7.52%
- Veröffentlicht 26.06.2007 22:30:00
- Zuletzt bearbeitet 16.06.2026 22:40:27
Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.
CVE-2007-3409
- EPSS 3.49%
- Veröffentlicht 26.06.2007 18:30:00
- Zuletzt bearbeitet 16.06.2026 22:41:58
Net::DNS before 0.60, a Perl module, allows remote attackers to cause a denial of service (stack consumption) via a malformed compressed DNS packet with self-referencing pointers, which triggers an infinite loop.
CVE-2007-2833
- EPSS 1.96%
- Veröffentlicht 21.06.2007 20:30:00
- Zuletzt bearbeitet 16.06.2026 22:40:31
Emacs 21 allows user-assisted attackers to cause a denial of service (crash) via certain crafted images, as demonstrated via a GIF image in vm mode, related to image size calculation.