- EPSS 11.29%
- Veröffentlicht 31.12.2005 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and ...
- EPSS 9.17%
- Veröffentlicht 31.12.2005 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
- EPSS 0.95%
- Veröffentlicht 31.12.2005 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the "chroot barrier" with util-vserver, which allows attackers to access files on the host system that are outside of the...
CVE-2005-4178
- EPSS 1.72%
- Veröffentlicht 12.12.2005 21:03:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code via unspecified inputs that cause insufficient memory to be allocated due to an incorrect expression that does not enforce the proper order of operati...
CVE-2005-3912
- EPSS 12.45%
- Veröffentlicht 30.11.2005 11:03:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remote attackers to cause a denial of service (crash or memory consumption) and possibly execute arbitrary...
CVE-2005-3847
- EPSS 0.07%
- Veröffentlicht 27.11.2005 00:03:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is performing ...
CVE-2005-3323
- EPSS 2.3%
- Veröffentlicht 27.10.2005 10:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.
CVE-2005-3302
- EPSS 6.2%
- Veröffentlicht 24.10.2005 10:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
CVE-2005-3274
- EPSS 0.09%
- Veröffentlicht 21.10.2005 01:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Race condition in ip_vs_conn_flush in Linux 2.6 before 2.6.13 and 2.4 before 2.4.32-pre2, when running on SMP systems, allows local users to cause a denial of service (null dereference) by causing a connection timer to expire while the connection tab...
CVE-2005-3120
- EPSS 30.44%
- Veröffentlicht 17.10.2005 20:06:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.