CVE-2008-0005
- EPSS 7.14%
- Veröffentlicht 12.01.2008 00:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.
CVE-2008-0226
- EPSS 91.94%
- Veröffentlicht 10.01.2008 23:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yass...
- EPSS 0.93%
- Veröffentlicht 09.01.2008 21:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted reg...
CVE-2007-6353
- EPSS 2.34%
- Veröffentlicht 20.12.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in exif.cpp in exiv2 library allows context-dependent attackers to execute arbitrary code via a crafted EXIF file that triggers a heap-based buffer overflow.
CVE-2007-5000
- EPSS 88.67%
- Veröffentlicht 13.12.2007 18:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inje...
CVE-2007-6206
- EPSS 0.08%
- Veröffentlicht 04.12.2007 00:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might ...
CVE-2007-4829
- EPSS 1.8%
- Veröffentlicht 02.11.2007 16:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in the Archive::Tar Perl module 1.36 and earlier allows user-assisted remote attackers to overwrite arbitrary files via a TAR archive that contains a file whose name is an absolute path or has ".." sequences.
CVE-2007-5268
- EPSS 15.26%
- Veröffentlicht 08.10.2007 21:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
pngrtran.c in libpng before 1.0.29 and 1.2.x before 1.2.21 use (1) logical instead of bitwise operations and (2) incorrect comparisons, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG image.
CVE-2007-5191
- EPSS 0.1%
- Veröffentlicht 04.10.2007 16:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
CVE-2007-4988
- EPSS 1.99%
- Veröffentlicht 24.09.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overfl...