Search

Search Results (334387 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2007-3732 1 Linux 1 Linux Kernel 2024-11-21 5.5 Medium
In Linux 2.6 before 2.6.23, the TRACE_IRQS_ON function in iret_exc calls a C function without ensuring that the segments are set properly. The kernel's %fs needs to be restored before the call in TRACE_IRQS_ON and before enabling interrupts, so that "current" references work. Without this, "current" used in the window between iret_exc and the middle of error_code where %fs is reset, would crash.
CVE-2007-20001 1 Starwindsoftware 1 Iscsi San 2024-11-21 7.5 High
A flaw was found in StarWind iSCSI target. An attacker could script standard iSCSI Initiator operation(s) to exhaust the StarWind service socket, which could lead to denial of service. This affects iSCSI SAN (Windows Native) Version 3.2.2 build 2007-02-20.
CVE-2007-10003 1 Wp-plugins 1 The Hackers Diet 2024-11-21 6.3 Medium
A vulnerability, which was classified as critical, has been found in The Hackers Diet Plugin up to 0.9.6b on WordPress. This issue affects some unknown processing of the file ajax_blurb.php of the component HTTP POST Request Handler. The manipulation of the argument user leads to sql injection. The attack may be initiated remotely. Upgrading to version 0.9.7b is able to address this issue. The patch is named 7dd8acf7cd8442609840037121074425d363b694. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-243803.
CVE-2007-0899 2 Clamav, Debian 2 Clamav, Debian Linux 2024-11-21 9.8 Critical
There is a possible heap overflow in libclamav/fsg.c before 0.100.0.
CVE-2007-0158 1 Acme 1 Thttpd 2024-11-21 9.8 Critical
thttpd 2007 has buffer underflow.
CVE-2006-7254 1 Gnu 1 Glibc 2024-11-21 N/A
The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allowing local users to carry out a denial of service attack on the daemon.
CVE-2006-7246 3 Gnome, Opensuse, Suse 4 Networkmanager, Opensuse, Linux Enterprise Desktop and 1 more 2024-11-21 6.8 Medium
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
CVE-2006-4245 2 Archivemail Project, Debian 2 Archivemail, Debian Linux 2024-11-21 8.1 High
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
CVE-2006-4243 1 Linux-vserver 1 Linux-vserver 2024-11-21 9.8 Critical
linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.
CVE-2006-3100 1 Termpkg Project 1 Termpkg 2024-11-21 9.8 Critical
termpkg 3.3 suffers from buffer overflow.
CVE-2006-10001 1 Markjaquith 1 Subscribe To Comments 2024-11-21 3.5 Low
A vulnerability, which was classified as problematic, was found in Subscribe to Comments Plugin up to 2.0.7 on WordPress. This affects an unknown part of the file subscribe-to-comments.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 2.0.8 is able to address this issue. The identifier of the patch is 9683bdf462fcac2f32b33be98f0b96497fbd1bb6. It is recommended to upgrade the affected component. The identifier VDB-222321 was assigned to this vulnerability.
CVE-2006-0062 1 Sillycycle 1 Xlockmore 2024-11-21 9.8 Critical
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a new Gaim window.
CVE-2006-0061 1 Sillycycle 1 Xlockmore 2024-11-21 9.8 Critical
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.
CVE-2005-4891 1 Simplemachines 1 Simple Machine Forum 2024-11-21 9.8 Critical
Simple Machine Forum (SMF) versions 1.0.4 and earlier have an SQL injection vulnerability that allows remote attackers to inject arbitrary SQL statements.
CVE-2005-4890 3 Debian, Redhat, Sudo Project 4 Debian Linux, Shadow, Enterprise Linux and 1 more 2024-11-21 7.8 High
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process.
CVE-2005-3590 1 Gnu 1 Glibc 2024-11-21 N/A
The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corrupt memory.
CVE-2005-3056 1 Twiki 1 Twiki 2024-11-21 9.8 Critical
TWiki allows arbitrary shell command execution via the Include function
CVE-2005-2354 1 Nvu 1 Nvu 2024-11-20 9.8 Critical
Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.
CVE-2005-2352 1 Gs-gpl Project 1 Gs-gpl 2024-11-20 8.1 High
I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.
CVE-2005-2351 2 Debian, Mutt 2 Debian Linux, Mutt 2024-11-20 5.5 Medium
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.