Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.1
CVE-2004-0594EPSS 55%

The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, all…

Fix: 4.3.7+
Fix from $1,600 2004-07-27
Debian Linux CRITICAL 9.8
CVE-2004-0434EPSS 7%

k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing …

Fix: 0.6.2+
Fix from $2,300 2004-07-07
Debian Linux HIGH 7.5
CVE-2004-0398EPSS 5%

Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before…

Fix: 0.22.0+
Fix from $1,950 2004-07-07
Debian Linux MEDIUM 6.8
CVE-2004-0179EPSS 11%

Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4…

Fix: 0.24.5+
Fix from $1,600 2004-06-01
Debian Linux HIGH 10.0
CVE-2003-0648EPSS 5%

Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.

Patch available
Fix from $1,950 2004-05-04
Debian Linux MEDIUM 5.0
CVE-2004-1180

Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (a…

Patch available
Fix from $1,600 2004-02-16
Fsp HIGH 7.5
CVE-2003-1022

Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory.

Fix: after 2.81.b18
Fix from $1,950 2004-01-20
Fsp HIGH 7.5
CVE-2004-0011

Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code.

Fix: after 2.81.b18
Fix from $1,950 2004-01-20
Debian Linux HIGH 7.5
CVE-2003-0360

Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code.

Patch available
Fix from $1,950 2003-06-09
Debian Linux HIGH 7.5
CVE-2003-0361

gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unaut…

Patch available
Fix from $1,950 2003-06-09
Debian Linux MEDIUM 5.0
CVE-2003-0362

Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines.

Mitigation only
Fix from $1,600 2003-06-09
Debian Linux HIGH 7.2
CVE-2003-0308

The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privil…

Patch available
Fix from $1,950 2003-05-15
Debian Linux HIGH 10.0
CVE-2003-0098EPSS 5%

Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings…

Fix: 3.8.6 / 3.10.5+
Fix from $1,950 2003-03-03
Debian Linux HIGH 7.5
CVE-2002-1372

Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could…

Fix: after 1.1.17
Fix from $1,950 2002-12-26
Debian Linux HIGH 10.0
CVE-2002-1235EPSS 15%

The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2…

Fix: 0.5.1 / 1.2.1+
Fix from $1,950 2002-11-04
Debian Linux MEDIUM 5.0
CVE-2002-1232

Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (me…

Patch available
Fix from $1,600 2002-11-04
Netstd HIGH 7.5
CVE-2002-0910

Buffer overflows in netstd 3.07-17 package allows remote DNS servers to execute arbitrary code via a long FQDN reply, as observed in the utilities (1…

Patch available
Fix from $1,950 2002-10-04
Debian Linux MEDIUM 5.0
CVE-2002-0912

in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properly terminate long strings, which allows remote att…

Patch available
Fix from $1,600 2002-10-04
Debian Linux HIGH 7.5
CVE-2002-0401EPSS 6%

SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed pack…

Fix: after 0.9.3
Fix from $1,950 2002-06-18
Debian Linux HIGH 7.8
CVE-2002-0184

Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via…

Fix: 1.6.6+
Fix from $1,950 2002-05-16
Debian Linux HIGH 7.2
CVE-2002-0062

Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "r…

Fix: 5.0+
Fix from $1,950 2002-03-08
Debian Linux HIGH 7.2
CVE-2002-0004

Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to fre…

Patch available
Fix from $1,950 2002-02-27
Debian Linux HIGH 7.2
CVE-2001-1561

Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments.

Patch available
Fix from $1,950 2001-12-31
Debian Linux HIGH 7.5
CVE-2001-0755

Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a …

Mitigation only
Fix from $1,950 2001-10-18
Debian Linux HIGH 7.5
CVE-2001-0763EPSS 17%

Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is n…

Fix: after 2.1.8.8.p3-1.1
Fix from $1,950 2001-10-18
Debian Linux MEDIUM 5.0
CVE-2001-0738

LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes…

Patch available
Fix from $1,600 2001-10-18
Debian Linux MEDIUM 5.0
CVE-2001-0977

slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding…

Patch available
Fix from $1,600 2001-07-16
Debian Linux HIGH 7.5
CVE-2001-0441

Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands…

Fix: after 2.2
Fix from $1,950 2001-06-27
Debian Linux HIGH 7.5
CVE-2001-0456EPSS 6%

postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymo…

Patch available
Fix from $1,950 2001-06-27
Debian Linux HIGH 7.5
CVE-2001-0458

Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.

Patch available
Fix from $1,950 2001-06-27