- EPSS 11.27%
- Published 10.06.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet.
CVE-2005-0005
- EPSS 3.5%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
CVE-2005-0077
- EPSS 0.07%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
CVE-2005-0988
- EPSS 0.12%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip af...
- EPSS 1.03%
- Published 02.05.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.
CVE-2005-0206
- EPSS 6.53%
- Published 27.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
CVE-2005-0754
- EPSS 2.28%
- Published 22.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
CVE-2004-1004
- EPSS 0.95%
- Published 14.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
CVE-2004-1005
- EPSS 1.11%
- Published 14.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
- EPSS 1.29%
- Published 14.04.2005 04:00:00
- Last modified 03.04.2025 01:03:51
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.