CVE-2003-0144
- EPSS 0.25%
- Veröffentlicht 31.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Buffer overflow in the lprm command in the lprold lpr package on SuSE 7.1 through 7.3, OpenBSD 3.2 and earlier, and possibly other operating systems, allows local users to gain root privileges via long command line arguments such as (1) request ID or...
CVE-2003-0028
- EPSS 56.05%
- Veröffentlicht 25.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via ...
- EPSS 13.07%
- Veröffentlicht 03.03.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cry...
CVE-2003-0015
- EPSS 37.01%
- Veröffentlicht 07.02.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed Directory request, as demonstrated by bypassing write checks to execute Update-prog and Check...
- EPSS 3.43%
- Veröffentlicht 17.01.2003 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.
CVE-2002-1667
- EPSS 0.06%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The virtual memory management system in FreeBSD 4.5-RELEASE and earlier does not properly check the existence of a VM object during page invalidation, which allows local users to cause a denial of service (crash) by calling msync on an unaccessed mem...
CVE-2002-1669
- EPSS 0.05%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
pkg_add in FreeBSD 4.2 through 4.4 creates a temporary directory with world-searchable permissions, which may allow local users to modify world-writable parts of the package during installation.
CVE-2002-1674
- EPSS 0.06%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
procfs on FreeBSD before 4.5 allows local users to cause a denial of service (kernel panic) by removing a file that the fstatfs function refers to.
CVE-2002-1915
- EPSS 0.23%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
tip on multiple BSD-based operating systems allows local users to cause a denial of service (execution prevention) by using flock() to lock the /var/log/acculog file.
CVE-2002-2092
- EPSS 0.07%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Race condition in exec in OpenBSD 4.0 and earlier, NetBSD 1.5.2 and earlier, and FreeBSD 4.4 and earlier allows local users to gain privileges by attaching a debugger to a process before the kernel has determined that the process is setuid or setgid.