CVE-2006-3918
- EPSS 91.37%
- Published 28.07.2006 00:04:00
- Last modified 03.04.2025 01:03:51
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected ba...
CVE-2006-2935
- EPSS 0.22%
- Published 05.07.2006 18:05:00
- Last modified 03.04.2025 01:03:51
The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device ...
- EPSS 10.35%
- Published 30.05.2006 19:02:00
- Last modified 03.04.2025 01:03:51
ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.
CVE-2006-2275
- EPSS 3.17%
- Published 09.05.2006 20:02:00
- Last modified 03.04.2025 01:03:51
Linux SCTP (lksctp) before 2.6.17 allows remote attackers to cause a denial of service (deadlock) via a large number of small messages to a receiver application that cannot process the messages quickly enough, which leads to "spillover of the receive...
CVE-2006-1727
- EPSS 5.04%
- Published 14.04.2006 10:02:00
- Last modified 03.04.2025 01:03:51
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to t...
CVE-2006-1728
- EPSS 29.8%
- Published 14.04.2006 10:02:00
- Last modified 03.04.2025 01:03:51
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypt...
CVE-2006-1729
- EPSS 1.82%
- Published 14.04.2006 10:02:00
- Last modified 03.04.2025 01:03:51
Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file...
CVE-2006-1741
- EPSS 1.95%
- Published 14.04.2006 10:02:00
- Last modified 03.04.2025 01:03:51
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new p...
CVE-2005-4807
- EPSS 13.59%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
CVE-2005-4808
- EPSS 1.13%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file.