CVE-2005-3181
- EPSS 0.15%
- Veröffentlicht 12.10.2005 13:04:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a m...
CVE-2005-2960
- EPSS 0.07%
- Veröffentlicht 05.10.2005 19:02:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.
CVE-2005-3106
- EPSS 0.08%
- Veröffentlicht 30.09.2005 10:05:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just per...
CVE-2005-2557
- EPSS 9.61%
- Veröffentlicht 28.09.2005 21:03:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Cross-site scripting (XSS) vulnerability in view_all_set.php in Mantis 0.19.0a1 through 1.0.0a3 allows remote attackers to inject arbitrary web script or HTML via the dir parameter, as identified by bug#0005959, and a different vulnerability than CVE...
CVE-2005-3055
- EPSS 0.09%
- Veröffentlicht 26.09.2005 19:03:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer ref...
- EPSS 15.08%
- Veröffentlicht 06.09.2005 23:03:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass inten...
CVE-2005-1855
- EPSS 0.06%
- Veröffentlicht 30.08.2005 11:45:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
- EPSS 5.31%
- Veröffentlicht 23.08.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointe...
CVE-2005-2555
- EPSS 0.09%
- Veröffentlicht 16.08.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.
- EPSS 1.33%
- Veröffentlicht 15.08.2005 04:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function...