Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.1 CVE-2004-0594EPSS 55% The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, all… Debian Linux 4.3.7+ Fix from $1,6002004-07-27 CRITICAL 9.8 CVE-2004-0434EPSS 7% k5admind (kadmind) for Heimdal allows remote attackers to execute arbitrary code via a Kerberos 4 compatibility administration request whose framing … Debian Linux 0.6.2+ Fix from $2,3002004-07-07 HIGH 7.5 CVE-2004-0398EPSS 5% Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before… Debian Linux 0.22.0+ Fix from $1,9502004-07-07 MEDIUM 6.8 CVE-2004-0179EPSS 11% Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4… Debian Linux 0.24.5+ Fix from $1,6002004-06-01 HIGH 10.0 CVE-2003-0648EPSS 5% Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code. Debian Linux Patch available Fix from $1,9502004-05-04 MEDIUM 5.0 CVE-2004-1180 Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (a… Debian Linux Patch available Fix from $1,6002004-02-16 HIGH 7.5 CVE-2003-1022 Directory traversal vulnerability in fsp before 2.81.b18 allows remote users to access files outside the FSP root directory. Fsp after 2.81.b18 Fix from $1,9502004-01-20 HIGH 7.5 CVE-2004-0011 Buffer overflow in fsp before 2.81.b18 allows remote users to execute arbitrary code. Fsp after 2.81.b18 Fix from $1,9502004-01-20 HIGH 7.5 CVE-2003-0360 Multiple buffer overflows in gPS before 1.0.0 allow attackers to cause a denial of service and possibly execute arbitrary code. Debian Linux Patch available Fix from $1,9502003-06-09 HIGH 7.5 CVE-2003-0361 gPS before 1.1.0 does not properly follow the rgpsp connection source acceptation policy as specified in the rgpsp.conf file, which could allow unaut… Debian Linux Patch available Fix from $1,9502003-06-09 MEDIUM 5.0 CVE-2003-0362 Buffer overflow in gPS before 0.10.2 may allow local users to cause a denial of service (SIGSEGV) in rgpsp via long command lines. Debian Linux Mitigation only Fix from $1,6002003-06-09 HIGH 7.2 CVE-2003-0308 The Sendmail 8.12.3 package in Debian GNU/Linux 3.0 does not securely create temporary files, which could allow local users to gain additional privil… Debian Linux Patch available Fix from $1,9502003-05-15 HIGH 10.0 CVE-2003-0098EPSS 5% Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings… Debian Linux 3.8.6 / 3.10.5+ Fix from $1,9502003-03-03 HIGH 7.5 CVE-2002-1372 Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly check the return values of various file and socket operations, which could… Debian Linux after 1.1.17 Fix from $1,9502002-12-26 HIGH 10.0 CVE-2002-1235EPSS 15% The kadm_ser_in function in (1) the Kerberos v4compatibility administration daemon (kadmind4) in the MIT Kerberos 5 (krb5) krb5-1.2.6 and earlier, (2… Debian Linux 0.5.1 / 1.2.1+ Fix from $1,9502002-11-04 MEDIUM 5.0 CVE-2002-1232 Memory leak in ypdb_open in yp_db.c for ypserv before 2.5 in the NIS package 3.9 and earlier allows remote attackers to cause a denial of service (me… Debian Linux Patch available Fix from $1,6002002-11-04 HIGH 7.5 CVE-2002-0910 Buffer overflows in netstd 3.07-17 package allows remote DNS servers to execute arbitrary code via a long FQDN reply, as observed in the utilities (1… Netstd Patch available Fix from $1,9502002-10-04 MEDIUM 5.0 CVE-2002-0912 in.uucpd UUCP server in Debian GNU/Linux 2.2, and possibly other operating systems, does not properly terminate long strings, which allows remote att… Debian Linux Patch available Fix from $1,6002002-10-04 HIGH 7.5 CVE-2002-0401EPSS 6% SMB dissector in Ethereal 0.9.3 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via malformed pack… Debian Linux after 0.9.3 Fix from $1,9502002-06-18 HIGH 7.8 CVE-2002-0184 Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local users to gain root privileges via… Debian Linux 1.6.6+ Fix from $1,9502002-05-16 HIGH 7.2 CVE-2002-0062 Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "r… Debian Linux 5.0+ Fix from $1,9502002-03-08 HIGH 7.2 CVE-2002-0004 Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to fre… Debian Linux Patch available Fix from $1,9502002-02-27 HIGH 7.2 CVE-2001-1561 Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -T arguments. Debian Linux Patch available Fix from $1,9502001-12-31 HIGH 7.5 CVE-2001-0755 Buffer overflow in ftp daemon (ftpd) 6.2 in Debian GNU/Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a … Debian Linux Mitigation only Fix from $1,9502001-10-18 HIGH 7.5 CVE-2001-0763EPSS 17% Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a long ident response, which is n… Debian Linux after 2.1.8.8.p3-1.1 Fix from $1,9502001-10-18 MEDIUM 5.0 CVE-2001-0738 LogLine function in klogd in sysklogd 1.3 in various Linux distributions allows an attacker to cause a denial of service (hang) by causing null bytes… Debian Linux Patch available Fix from $1,6002001-10-18 MEDIUM 5.0 CVE-2001-0977 slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding… Debian Linux Patch available Fix from $1,6002001-07-16 HIGH 7.5 CVE-2001-0441 Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands… Debian Linux after 2.2 Fix from $1,9502001-06-27 HIGH 7.5 CVE-2001-0456EPSS 6% postinst installation script for Proftpd in Debian 2.2 does not properly change the "run as uid/gid root" configuration when the user enables anonymo… Debian Linux Patch available Fix from $1,9502001-06-27 HIGH 7.5 CVE-2001-0458 Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands. Debian Linux Patch available Fix from $1,9502001-06-27