CVE-2005-1855
- EPSS 0.36%
- Veröffentlicht 30.08.2005 11:45:00
- Zuletzt bearbeitet 16.06.2026 22:13:48
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
- EPSS 4.63%
- Veröffentlicht 23.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:14:55
The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointe...
CVE-2005-2555
- EPSS 0.45%
- Veröffentlicht 16.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:15:11
Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.
- EPSS 3%
- Veröffentlicht 15.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:13:12
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function...
CVE-2005-2498
- EPSS 5.09%
- Veröffentlicht 15.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:15:00
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certai...
- EPSS 8.39%
- Veröffentlicht 05.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:12:45
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one...
CVE-2005-2456
- EPSS 0.38%
- Veröffentlicht 04.08.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:14:55
Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFRM_POLICY_OU...
CVE-2005-1920
- EPSS 3.67%
- Veröffentlicht 26.07.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:13:55
The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive info...
CVE-2005-1689
- EPSS 11.01%
- Veröffentlicht 18.07.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:13:30
Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.
CVE-2005-1916
- EPSS 0.36%
- Veröffentlicht 06.07.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:13:54
linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.