Vulnerability index

Browse CVEs

102 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nview HIGH 7.2
CVE-2005-4595

Untrusted search path vulnerability (RPATH) in XnView 1.70 and NView 4.51 on Gentoo Linux allows local users to execute arbitrary code via a maliciou…

Patch available
Fix from $1,950 2005-12-31
Qt Unixodbc HIGH 7.2
CVE-2005-4279

Untrusted search path vulnerability in Qt-UnixODBC before 3.3.4-r1 on Gentoo Linux allows local users in the portage group to gain privileges via a m…

Fix: after 3.3.3
Fix from $1,950 2005-12-16
Linux Eix MEDIUM 5.0
CVE-2005-3785

Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symli…

Fix: after 0.3
Fix from $1,600 2005-11-23
Linux MEDIUM 5.0
CVE-2005-1267EPSS 14%

The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attacke…

Patch available
Fix from $1,600 2005-06-10
Poppassd Pam HIGH 10.0
CVE-2005-0002

poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote at…

Fix: after 1.0
Fix from $1,950 2005-05-02
Webmin MEDIUM 5.0
CVE-2005-0427

The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webm…

Patch available
Fix from $1,600 2005-05-02
Linux MEDIUM 5.0
CVE-2005-1121

Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd…

Patch available
Fix from $1,600 2005-05-02
Linux MEDIUM 5.0
CVE-2005-0470

Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet…

Patch available
Fix from $1,600 2005-03-14
Linux MEDIUM 5.1
CVE-2005-0667

Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with…

Patch available
Fix from $1,600 2005-03-07
Linux HIGH 10.0
CVE-2004-0990EPSS 28%

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and …

Patch available
Fix from $1,950 2005-03-01
Linux HIGH 10.0
CVE-2004-1034EPSS 6%

Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a d…

Patch available
Fix from $1,950 2005-03-01
Linux HIGH 10.0
CVE-2004-1037EPSS 62%

The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.

Patch available
Fix from $1,950 2005-03-01
Linux HIGH 7.2
CVE-2004-1031

fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to bypass access restrictions and load an arbitrary configuration…

Patch available
Fix from $1,950 2005-03-01
Linux MEDIUM 6.8
CVE-2004-1036

Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.…

Patch available
Fix from $1,600 2005-03-01
Linux MEDIUM 6.8
CVE-2004-1055

Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML…

No fix yet
Fix from $1,600 2005-03-01
Linux MEDIUM 5.0
CVE-2004-1027

Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj ar…

Patch available
Fix from $1,600 2005-03-01
Linux HIGH 7.5
CVE-2005-0535

Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unaut…

Patch available
Fix from $1,950 2005-02-22
Linux HIGH 10.0
CVE-2004-0947EPSS 7%

Buffer overflow in unarj before 2.63a-r2 allows remote attackers to execute arbitrary code via an arj archive that contains long filenames.

Patch available
Fix from $1,950 2005-02-09
Linux HIGH 7.5
CVE-2004-0937EPSS 15%

Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protecti…

Patch available
Fix from $1,950 2005-02-09
Linux HIGH 10.0
CVE-2004-0891EPSS 7%

Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possi…

Mitigation only
Fix from $1,950 2005-01-27
Linux HIGH 7.5
CVE-2004-0932EPSS 66%

McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to b…

Patch available
Fix from $1,950 2005-01-27
Linux HIGH 7.5
CVE-2004-0933EPSS 21%

Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content M…

Patch available
Fix from $1,950 2005-01-27
Linux HIGH 7.5
CVE-2004-0934EPSS 15%

Kaspersky 3.x to 4.x allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, whi…

Patch available
Fix from $1,950 2005-01-27
Linux HIGH 7.5
CVE-2004-0935EPSS 15%

Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and g…

Patch available
Fix from $1,950 2005-01-27
Linux HIGH 7.5
CVE-2004-0936EPSS 15%

RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does…

Patch available
Fix from $1,950 2005-01-27
Linux MEDIUM 5.0
CVE-2004-0918EPSS 16%

The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of s…

Patch available
Fix from $1,600 2005-01-27
Linux HIGH 10.0
CVE-2004-0914EPSS 9%

Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-b…

Patch available
Fix from $1,950 2005-01-10
Linux HIGH 10.0
CVE-2004-1025EPSS 5%

Multiple heap-based buffer overflows in imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote attackers to cau…

Patch available
Fix from $1,950 2005-01-10
Linux HIGH 10.0
CVE-2004-1026

Multiple integer overflows in the image handler for imlib 1.9.14 and earlier, which is used by gkrellm and several window managers, allow remote atta…

Patch available
Fix from $1,950 2005-01-10
Linux HIGH 10.0
CVE-2004-1304EPSS 11%

Stack-based buffer overflow in the ELF header parsing code in file before 4.12 allows attackers to execute arbitrary code via a crafted ELF file.

Patch available
Fix from $1,950 2005-01-10