Vulnerability index

Browse CVEs

2,592 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 7.5
CVE-2003-0434EPSS 41%

Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters …

Patch available
Fix from $1,950 2003-07-24
Linux HIGH 10.0
CVE-2003-0248

The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.

Patch available
Fix from $1,950 2003-06-16
Linux HIGH 7.5
CVE-2003-0354

Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript f…

Patch available
Fix from $1,950 2003-06-16
Linux HIGH 7.2
CVE-2002-1155

Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.

Patch available
Fix from $1,950 2003-06-16
Linux MEDIUM 5.0
CVE-2003-0247

Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").

Patch available
Fix from $1,600 2003-06-16
Linux MEDIUM 5.0
CVE-2003-0364

The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain pa…

Patch available
Fix from $1,600 2003-06-16
Lv HIGH 7.2
CVE-2003-0188

lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious…

Patch available
Fix from $1,950 2003-06-09
Linux HIGH 7.5
CVE-2003-0135

vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertentl…

Patch available
Fix from $1,950 2003-04-11
Linux HIGH 10.0
CVE-2003-0041

Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.

Patch available
Fix from $1,950 2003-02-19
Linux HIGH 7.2
CVE-2002-1160

The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges…

Mitigation only
Fix from $1,950 2003-02-19
Linux HIGH 7.2
CVE-2003-0019

uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces…

Patch available
Fix from $1,950 2003-02-19
Redhat Package Manager HIGH 7.5
CVE-2002-2204

The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow…

Patch available
Fix from $1,950 2002-12-31
Linux HIGH 7.5
CVE-2002-0836EPSS 8%

dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary …

Patch available
Fix from $1,950 2002-10-28
Pre Execution Environment MEDIUM 5.0
CVE-2002-0835EPSS 7%

Preboot eXecution Environment (PXE) server allows remote attackers to cause a denial of service (crash) via certain DHCP packets from Voice-Over-IP (…

Patch available
Fix from $1,600 2002-10-04
Interchange MEDIUM 5.0
CVE-2002-0874EPSS 6%

Vulnerability in Interchange 4.8.6, 4.8.3, and other versions, when running in INET mode, allows remote attackers to read arbitrary files.

Patch available
Fix from $1,600 2002-09-05
Linux HIGH 7.2
CVE-2000-1208

Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an im…

Patch available
Fix from $1,950 2002-08-12
Linux HIGH 7.2
CVE-2002-0506

Buffer overflow in newt.c of newt windowing library (libnewt) 0.50.33 and earlier may allow attackers to cause a denial of service or execute arbitra…

Mitigation only
Fix from $1,950 2002-08-12
Linux MEDIUM 6.2
CVE-2002-0638

setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary f…

Patch available
Fix from $1,600 2002-08-12
Linux HIGH 7.5
CVE-2002-0067

Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote attackers …

Fix: after 2.4_stable_2
Fix from $1,950 2002-03-08
Linux HIGH 7.5
CVE-2002-0068EPSS 9%

Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL…

Fix: after 2.4_stable_3
Fix from $1,950 2002-03-08
Linux HIGH 7.5
CVE-2002-0002EPSS 5%

Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to exe…

Patch available
Fix from $1,950 2002-01-31
Linux HIGH 7.5
CVE-2002-0045

slapd in OpenLDAP 2.0 through 2.0.19 allows local users, and anonymous users before 2.0.8, to conduct a "replace" action on access controls without a…

Fix: after 2.0.19
Fix from $1,950 2002-01-31
Linux Powertools HIGH 7.5
CVE-2001-0869

Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote att…

Patch available
Fix from $1,950 2001-12-21
Linux HIGH 7.2
CVE-2001-0872

OpenSSH 3.0.1 and earlier with UseLogin enabled does not properly cleanse critical environment variables such as LD_PRELOAD, which allows local users…

Fix: after 3.0.1
Fix from $1,950 2001-12-21
Linux HIGH 7.5
CVE-2001-0889EPSS 6%

Exim 3.22 and earlier, in some configurations, does not properly verify the local part of an address when redirecting the address to a pipe, which co…

Fix: after 3.22
Fix from $1,950 2001-12-19
Linux MEDIUM 5.0
CVE-2001-0852EPSS 9%

TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header.

Mitigation only
Fix from $1,600 2001-12-06
Linux MEDIUM 5.0
CVE-2001-0859

2.4.3-12 kernel in Red Hat Linux 7.1 Korean installation program sets the setting default umask for init to 000, which installs files with world-writ…

Patch available
Fix from $1,600 2001-12-06
Stronghold MEDIUM 5.0
CVE-2001-0868

Red Hat Stronghold 2.3 to 3.0 allows remote attackers to retrieve system information via an HTTP GET request to (1) stronghold-info or (2) stronghold…

Fix: after 3.0
Fix from $1,600 2001-11-28
Redhat Package Manager HIGH 7.2
CVE-2001-0923

RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.

Patch available
Fix from $1,950 2001-10-25
Linux MEDIUM 6.2
CVE-2001-1383

initscript in setserial 2.17-4 and earlier uses predictable temporary file names, which could allow local users to conduct unauthorized operations on…

Patch available
Fix from $1,600 2001-09-26