|
303801
|
9.8 |
CRITICAL
Network
|
sillycycle
|
xlockmore
|
xlockmore 5.13 and 5.22 segfaults when using libpam-opensc and returns the underlying xsession. This allows unauthorized users access to the X session.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2006-0061
|
2024-11-21 09:05 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303802
|
7.8 |
HIGH
Local
|
sudo_project debian redhat
|
sudo shadow debian_linux enterprise_linux
|
There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to …
|
CWE-20
Improper Input Validation
|
CVE-2005-4890
|
2024-11-21 09:05 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303803
|
5.9 |
MEDIUM
Network
|
google
|
chrome
|
SHA-1 is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of SHA-1 in TLS 1.2. NOTE: this CVE exists …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2005-4900
|
2024-11-21 09:05 |
2016-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303804
|
- |
|
csilvers
|
gperftools
|
Multiple integer overflows in TCMalloc (tcmalloc.cc) in gperftools before 0.4 make it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large siz…
|
CWE-189
Numeric Errors
|
CVE-2005-4895
|
2024-11-21 09:05 |
2012-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303805
|
9.8 |
CRITICAL
Network
|
gnu
|
glibc
|
The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buf…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2005-3590
|
2024-11-21 09:02 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303806
|
9.8 |
CRITICAL
Network
|
twiki
|
twiki
|
TWiki allows arbitrary shell command execution via the Include function
|
CWE-74
Injection
|
CVE-2005-3056
|
2024-11-21 09:01 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303807
|
9.8 |
CRITICAL
Network
|
nvu
|
nvu
|
Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.
|
NVD-CWE-noinfo
|
CVE-2005-2354
|
2024-11-21 08:59 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303808
|
8.1 |
HIGH
Network
|
gs-gpl_project
|
gs-gpl
|
I race condition in Temp files was found in gs-gpl before 8.56 addons scripts.
|
CWE-362
Race Condition
|
CVE-2005-2352
|
2024-11-21 08:59 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303809
|
5.5 |
MEDIUM
Local
|
mutt debian
|
mutt debian_linux
|
Mutt before 1.5.20 patch 7 allows an attacker to cause a denial of service via a series of requests to mutt temporary files.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2005-2351
|
2024-11-21 08:59 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303810
|
6.1 |
MEDIUM
Network
|
websieve_project
|
websieve
|
Cross-site scripting (XSS) vulnerability in websieve v0.62 allows remote attackers to inject arbitrary web script or HTML code in the web user interface.
|
CWE-79
Cross-site Scripting
|
CVE-2005-2350
|
2024-11-21 08:59 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|