Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2006-5873

Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows rem…

Patch available
Fix from $1,950 2006-12-12
Debian Linux HIGH 9.3
CVE-2006-5868

Multiple buffer overflows in Imagemagick 6.0 before 6.0.6.2, and 6.2 before 6.2.4.5, has unknown impact and user-assisted attack vectors via a crafte…

Fix: 6.0.6.2 / 6.2.4.5+
Fix from $1,950 2006-11-22
Debian Linux HIGH 8.1
CVE-2006-5051EPSS 45%

Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code…

Fix: 10.3.9+
Fix from $1,950 2006-09-27
Debian Linux MEDIUM 5.0
CVE-2006-2661EPSS 16%

ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.

Fix: 2.2+
Fix from $1,600 2006-05-30
Debian Linux HIGH 7.6
CVE-2006-1244

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml…

Patch available
Fix from $1,950 2006-03-15
Kernel Patch Vserver MEDIUM 5.0
CVE-2005-4347

The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the "chroot barrier"…

Fix: 1.9.5.5 / 2.2+
Fix from $1,600 2005-12-31
Debian Linux MEDIUM 6.5
CVE-2005-4178

Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code via unspecified inputs that cause insufficient me…

Fix: 0.47+
Fix from $1,600 2005-12-12
Debian Linux HIGH 7.5
CVE-2005-3912EPSS 14%

Format string vulnerability in miniserv.pl Perl web server in Webmin before 1.250 and Usermin before 1.180, with syslog logging enabled, allows remot…

Fix: 1.180 / 1.250+
Fix from $1,950 2005-11-30
Debian Linux HIGH 7.5
CVE-2005-3323

docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in Restructure…

Fix: 2.7.8 / 2.8.2+
Fix from $1,950 2005-10-27
Debian Linux HIGH 7.3
CVE-2005-3302

Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh fil…

No fix yet
Fix from $1,950 2005-10-24
Debian Linux CRITICAL 9.8
CVE-2005-3120EPSS 23%

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article…

Fix: after 2.8.6
Fix from $2,300 2005-10-17
Debian Linux HIGH 7.5
CVE-2005-2498EPSS 5%

Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew,…

Fix: after 1.1.1
Fix from $1,950 2005-08-15
Apt Cacher HIGH 7.5
CVE-2005-1854

Unknown vulnerability in apt-cacher in Debian 3.1, related to "missing input sanitising," allows remote attackers to execute arbitrary commands on th…

Patch available
Fix from $1,950 2005-08-05
Debian Linux HIGH 7.5
CVE-2005-1920

The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on th…

Fix: after 3.4.0
Fix from $1,950 2005-07-26
Debian Linux CRITICAL 9.8
CVE-2005-1689EPSS 11%

Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code …

Fix: 10.4.2+
Fix from $2,300 2005-07-18
Debian Linux MEDIUM 5.5
CVE-2005-1916

linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.

Fix: after 2005-06-05
Fix from $1,600 2005-07-06
Debian Linux HIGH 7.5
CVE-2005-1796EPSS 5%

Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to ex…

Fix: 0.7.3+
Fix from $1,950 2005-05-31
Qpopper HIGH 7.2
CVE-2005-1151

qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or c…

Fix: after 4.0.4
Fix from $1,950 2005-05-25
Ppxp HIGH 7.2
CVE-2005-0392

ppxp does not drop root privileges before opening log files, which allows local users to execute arbitrary commands.

Mitigation only
Fix from $1,950 2005-05-19
Debian Linux HIGH 7.5
CVE-2005-0005

Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via…

Patch available
Fix from $1,950 2005-05-02
Debian Linux HIGH 7.5
CVE-2005-0211EPSS 22%

Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code vi…

Patch available
Fix from $1,950 2005-05-02
Debian Linux HIGH 7.5
CVE-2005-0206

The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributi…

Patch available
Fix from $1,950 2005-04-27
Debian Linux HIGH 7.5
CVE-2004-1004

Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.

Patch available
Fix from $1,950 2005-04-14
Debian Linux HIGH 7.5
CVE-2004-1005

Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.

Patch available
Fix from $1,950 2005-04-14
Debian Linux HIGH 7.5
CVE-2004-1175

fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacte…

Patch available
Fix from $1,950 2005-04-14
Debian Linux HIGH 7.5
CVE-2004-1176

Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute a…

Patch available
Fix from $1,950 2005-04-14
Debian Linux MEDIUM 5.0
CVE-2004-1009

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

Patch available
Fix from $1,600 2005-04-14
Debian Linux MEDIUM 5.0
CVE-2004-1090

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."

Patch available
Fix from $1,600 2005-04-14
Debian Linux MEDIUM 5.0
CVE-2004-1091

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.

Patch available
Fix from $1,600 2005-04-14
Debian Linux MEDIUM 5.0
CVE-2004-1092

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.

Patch available
Fix from $1,600 2005-04-14