Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora Core HIGH 7.2
CVE-2004-0619

Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and …

Patch available
Fix from $1,950 2004-12-06
Enterprise Linux HIGH 7.5
CVE-2004-0494

Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions vi…

Patch available
Fix from $1,950 2004-11-23
Enterprise Linux HIGH 7.5
CVE-2004-0750

Unknown vulnerability in redhat-config-nfs before 1.0.13, when shares are exported to multiple hosts, can produce incorrect permissions and prevent t…

Patch available
Fix from $1,950 2004-10-20
Enterprise Linux MEDIUM 5.0
CVE-2004-1613

Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains …

Patch available
Fix from $1,600 2004-10-18
Lha HIGH 10.0
CVE-2004-0234EPSS 10%

Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow…

Patch available
Fix from $1,950 2004-08-18
Lha MEDIUM 6.4
CVE-2004-0235

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containin…

Patch available
Fix from $1,600 2004-08-18
Libpng MEDIUM 5.0
CVE-2004-0421

The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image fil…

Patch available
Fix from $1,600 2004-08-18
Fedora Core HIGH 10.0
CVE-2004-0460EPSS 45%

Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial …

Patch available
Fix from $1,950 2004-08-06
Fedora Core HIGH 10.0
CVE-2004-0461EPSS 17%

The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C includ…

Patch available
Fix from $1,950 2004-08-06
Fedora Core MEDIUM 6.8
CVE-2004-0595EPSS 45%

The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input …

Patch available
Fix from $1,600 2004-07-27
Gdk Pixbuf MEDIUM 5.0
CVE-2004-0111

gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.

Patch available
Fix from $1,600 2004-04-15
Enterprise Linux HIGH 7.5
CVE-2004-0104EPSS 26%

Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

Fix: after 2.7
Fix from $1,950 2004-03-03
Enterprise Linux HIGH 7.5
CVE-2004-0105EPSS 8%

Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.

Fix: after 2.7
Fix from $1,950 2004-03-03
Bigmem Kernel HIGH 7.2
CVE-2004-0077

The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value f…

Patch available
Fix from $1,950 2004-03-03
Kernel HIGH 7.5
CVE-2003-0700

The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses secur…

Fix: after 2.4.21
Fix from $1,950 2004-02-17
Tcpdump HIGH 7.5
CVE-2003-0989EPSS 5%

tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than …

Fix: after 3.8.0
Fix from $1,950 2004-02-17
Rsync HIGH 7.5
CVE-2003-0962EPSS 21%

Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape …

Patch available
Fix from $1,950 2003-12-15
Interchange MEDIUM 5.0
CVE-2003-1138EPSS 5%

The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory contents, even if auto index…

No fix yet
Fix from $1,600 2003-10-27
Pam Smb HIGH 7.5
CVE-2003-0686EPSS 27%

Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary …

Patch available
Fix from $1,950 2003-10-20
Enterprise Linux HIGH 7.5
CVE-2003-0689

The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitr…

Patch available
Fix from $1,950 2003-10-20
Sendmail MEDIUM 5.0
CVE-2003-0688

The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allow…

Patch available
Fix from $1,600 2003-10-20
Wu Ftpd CRITICAL 9.8
CVE-2003-0466EPSS 78%

Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demon…

Fix: after 5.0
Fix from $2,300 2003-08-27
Up2date HIGH 7.5
CVE-2003-0546

up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed f…

Mitigation only
Fix from $1,950 2003-08-27
Enterprise Linux HIGH 7.5
CVE-2003-0699

The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may…

Patch available
Fix from $1,950 2003-08-27
Analog Real Time Synthesizer MEDIUM 5.0
CVE-2003-0459

KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer hea…

Patch available
Fix from $1,600 2003-08-27
Kdebase MEDIUM 5.0
CVE-2003-0548

The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a cho…

Patch available
Fix from $1,600 2003-08-27
Kdebase MEDIUM 5.0
CVE-2003-0549

The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a shor…

Patch available
Fix from $1,600 2003-08-27
Linux MEDIUM 5.0
CVE-2003-0550

The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.

Patch available
Fix from $1,600 2003-08-27
Linux MEDIUM 5.0
CVE-2003-0551

The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.

Patch available
Fix from $1,600 2003-08-27
Linux MEDIUM 5.0
CVE-2003-0552

Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.

Patch available
Fix from $1,600 2003-08-27