Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.0
CVE-2004-1093

Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."

Patch available
Fix from $1,600 2005-04-14
Debian Linux MEDIUM 5.0
CVE-2004-1174

direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."

Patch available
Fix from $1,600 2005-04-14
Debian Linux HIGH 10.0
CVE-2004-1052

Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an…

Patch available
Fix from $1,950 2005-03-01
Debian Linux HIGH 7.5
CVE-2004-0986

Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to f…

Patch available
Fix from $1,950 2005-03-01
Debian Linux HIGH 7.2
CVE-2004-1051

sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same…

Patch available
Fix from $1,950 2005-03-01
Bsmtpd HIGH 7.5
CVE-2005-0107

bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.

Fix: after 2.3
Fix from $1,950 2005-02-25
Debian Linux HIGH 10.0
CVE-2004-0964EPSS 63%

Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via ce…

Patch available
Fix from $1,950 2005-02-09
Debian Linux HIGH 10.0
CVE-2004-0980

Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, …

Patch available
Fix from $1,950 2005-02-09
Debian Linux HIGH 10.0
CVE-2004-0981EPSS 6%

Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.

Mitigation only
Fix from $1,950 2005-02-09
Debian Linux HIGH 10.0
CVE-2004-0888EPSS 9%

Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to …

Patch available
Fix from $1,950 2005-01-27
Debian Linux HIGH 10.0
CVE-2004-0889EPSS 6%

Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (cras…

Patch available
Fix from $1,950 2005-01-27
Debian Linux CRITICAL 9.8
CVE-2005-0102

Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code vi…

Fix: after 2.0.2
Fix from $2,300 2005-01-24
Debian Linux HIGH 10.0
CVE-2004-0994EPSS 5%

Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, wh…

Patch available
Fix from $1,950 2005-01-10
Debian Linux HIGH 10.0
CVE-2004-1095EPSS 9%

Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, …

Patch available
Fix from $1,950 2005-01-10
Debian Linux HIGH 7.2
CVE-2004-1076

Multiple buffer overflows in the RtConfigLoad function in rt-config.c for Atari800 before 1.3.4 allow local users to execute arbitrary code via large…

Patch available
Fix from $1,950 2005-01-10
Debian Linux MEDIUM 5.0
CVE-2004-0915

Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot …

Patch available
Fix from $1,600 2005-01-10
Debian Linux MEDIUM 5.0
CVE-2004-1014

statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process c…

Patch available
Fix from $1,600 2005-01-10
Debian Linux HIGH 10.0
CVE-2004-0451

Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote atta…

Patch available
Fix from $1,950 2004-12-06
Debian Linux HIGH 7.6
CVE-2004-0456

Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP …

Patch available
Fix from $1,950 2004-12-06
Debian Linux HIGH 7.2
CVE-2004-0455

Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.

Fix: 0.5.7+
Fix from $1,950 2004-12-06
Debian Linux MEDIUM 5.0
CVE-2002-1581EPSS 8%

Directory traversal vulnerability in nph-mr.cgi in Mailreader.com 2.3.20 through 2.3.31 allows remote attackers to view arbitrary files via .. (dot d…

Patch available
Fix from $1,600 2004-12-06
Netkit MEDIUM 5.0
CVE-2004-0911

telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of a…

Fix: after 0.17
Fix from $1,600 2004-11-03
Debian Linux CRITICAL 9.8
CVE-2004-0772EPSS 7%

Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbit…

Fix: after 1.2.8
Fix from $2,300 2004-10-20
Bsdmainutils HIGH 7.2
CVE-2004-0793

The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execu…

Patch available
Fix from $1,950 2004-10-20
Debian Linux HIGH 7.5
CVE-2004-0458

mah-jong before 1.6.2 allows remote attackers to cause a denial of service (server crash) via a missing argument, which triggers a null pointer deref…

Patch available
Fix from $1,950 2004-09-28
Debian Linux HIGH 7.5
CVE-2004-0642EPSS 8%

Double free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for…

Fix: after 1.3.4
Fix from $1,950 2004-09-28
Debian Linux HIGH 7.1
CVE-2004-0689

KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate…

Fix: 3.3+
Fix from $1,950 2004-09-28
Debian Linux HIGH 10.0
CVE-2004-0522

Gallery 1.4.3 and earlier allows remote attackers to bypass authentication and obtain Gallery administrator privileges.

Patch available
Fix from $1,950 2004-08-06
Debian Linux HIGH 7.2
CVE-2004-0579

Format string vulnerability in super before 3.23 allows local users to execute arbitrary code as root.

Patch available
Fix from $1,950 2004-08-06
Debian Linux MEDIUM 5.0
CVE-2004-0583

The account lockout functionality in (1) Webmin 1.140 and (2) Usermin 1.070 does not parse certain character strings, which allows remote attackers t…

Patch available
Fix from $1,600 2004-08-06