- EPSS 20.8%
- Published 25.10.2005 17:06:00
- Last modified 03.04.2025 01:03:51
Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused f...
CVE-2005-3181
- EPSS 0.15%
- Published 12.10.2005 13:04:00
- Last modified 03.04.2025 01:03:51
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a m...
CVE-2005-3106
- EPSS 0.08%
- Published 30.09.2005 10:05:00
- Last modified 03.04.2025 01:03:51
Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just per...
CVE-2005-2946
- EPSS 0.19%
- Published 16.09.2005 22:03:00
- Last modified 03.04.2025 01:03:51
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signatur...
CVE-2005-2492
- EPSS 0.07%
- Published 14.09.2005 19:03:00
- Last modified 03.04.2025 01:03:51
The raw_sendmsg function in the Linux kernel 2.6 before 2.6.13.1 allows local users to cause a denial of service (change hardware state) or read from arbitrary memory via crafted input.
- EPSS 11.69%
- Published 06.09.2005 23:03:00
- Last modified 03.04.2025 01:03:51
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass inten...
- EPSS 1.33%
- Published 15.08.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function...
- EPSS 9.8%
- Published 19.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").
CVE-2005-0758
- EPSS 0.15%
- Published 13.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
CVE-2005-1513
- EPSS 12.75%
- Published 11.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.