| Metric | ID | Date Public | Name |
|---|
| 37.96 | VU#200132 | 06/13/2003 | Various UNIX and Linux PDF readers/viewers execute commands embedded within hyperlinks |
| 36 | VU#953746 | 02/11/2003 | Oracle9i Database contains remotely exploitable buffer overflow in "ORACLE.EXE" |
| 29.72 | VU#542971 | 06/26/2002 | Multiple vendors' Domain Name System (DNS) stub resolvers vulnerable to buffer overflow via network name and address lookups |
| 29.72 | VU#803539 | 06/26/2002 | Multiple vendors' Domain Name System (DNS) stub resolvers vulnerable to buffer overflows |
| 28.12 | VU#971364 | 05/02/2003 | HP-UX "kermit" vulnerable to buffer overflow |
| 27.75 | VU#673993 | 04/09/2003 | PopTop PPTP Server contains buffer overflow in "ctrlpacket.c" |
| 27 | VU#663786 | 02/11/2003 | Oracle9i Database contains remotely exploitable buffer overflow in "BFILENAME" function |
| 27 | VU#743954 | 02/11/2003 | Oracle9i Database contains remotely exploitable buffer overflow in "TZ_OFFSET" function |
| 27 | VU#840666 | 02/11/2003 | Oracle9i Database contains remotely exploitable buffer overflow in "TO_TIMESTAMP_TZ" function |
| 26.52 | VU#981222 | 02/18/2004 | Linux kernel mremap(2) system call does not properly check return value from do_munmap() function |
| 25.98 | VU#176888 | 03/26/2001 | Linux kernel contains race condition via ptrace/procfs/execve |
| 25.81 | VU#179804 | 03/23/2004 | Common Desktop Environment (CDE) dtlogin XDMCP parser improperly deallocates memory |
| 25.65 | VU#737451 | 07/20/2001 | SSH Secure Shell sshd2 does not adequately authenticate logins to accounts with encrypted password fields containing two or fewer characters |
| 23.62 | VU#301156 | 12/01/2003 | Linux kernel do_brk() function contains integer overflow |
| 21.88 | VU#886083 | 04/30/2001 | WU-FTPD does not properly handle file name globbing |
| 21.37 | VU#798263 | 09/08/2001 | Taylor UUCP Package fails to properly filter command line arguments |
| 20.05 | VU#960877 | 11/04/2000 | Red Hat linux restore uses insecure environment variables allowing root compromise |
| 19.03 | VU#738331 | 10/01/2002 | Domain Name System (DNS) resolver libraries vulnerable to read buffer overflow |
| 18.87 | VU#153653 | 10/31/2000 | Linux dump uses environment variables insecurely, allowing for root compromise |
| 15.82 | VU#134025 | 02/07/2003 | kernel-utils sets insecure permissions on "uml_net" utility |
| 15.26 | VU#800635 | 01/25/2002 | rsync fails to properly handle negative values specified for signed integers thereby allowing remote command execution |
| 14.42 | VU#415734 | 03/10/2004 | F-Secure Anti-Virus for Linux fails to properly detect Sober.D virus |
| 14.4 | VU#226184 | 12/16/2004 | Samba vulnerable to integer overflow processing file security descriptors |
| 14.25 | VU#628849 | 03/17/2003 | ptrace contains vulnerability allowing for local root compromise |
| 13.53 | VU#490620 | 01/05/2004 | Linux kernel do_mremap() call creates virtual memory area of 0 bytes in length |
| 13.38 | VU#258564 | 07/14/2003 | Linux NFS utils package "rpc.mountd" contains off-by-one buffer overflow in xlog() function |
| 12.57 | VU#361181 | 09/26/2005 | Helix Player format string vulnerability |
| 12.15 | VU#914681 | 09/20/2005 | Mozilla Firefox fails to properly sanitize user-supplied URIs via shell script |
| 11.81 | VU#973654 | 06/14/2004 | Linux kernel fails to properly handle floating point signals generated by "fsave" and "frstor" |
| 11.05 | VU#124003 | 03/21/2002 | Apache HTTP Server on Win32 systems does not securely handle input passed to CGI programs |
| 10.96 | VU#405955 | 07/29/2002 | util-linux package vulnerable to privilege escalation when "ptmptmp" file is not removed properly when using "chfn" utility |
| 10.79 | VU#399883 | 07/26/2001 | Linux groff utility pic contains format string vulnerability |
| 10.68 | VU#121891 | 01/02/2002 | Buffer overflow vulnerability in grpck command line utility |
| 10.68 | VU#877811 | 01/02/2002 | Buffer overflow vulnerability in pwck command line utility |
| 10.54 | VU#653160 | 09/14/2004 | Mozilla Linux installer does not properly set file permissions |
| 10.26 | VU#405092 | 12/19/2006 | Mozilla products allows the src attribute in an img element to be changed to a JavaScript URI |
| 9.21 | VU#698640 | 02/08/2001 | Linux kernel does not properly validate user input via sysctl for negative value |
| 9 | VU#118277 | 10/18/2000 | The Oracle Internet Directory LDAP (oidldapd) contains buffer overflow |
| 8.9 | VU#971179 | 06/27/2001 | UUCP package contains multiple buffer overflows via long string of characters sent as command line argument |
| 8.77 | VU#685461 | 03/27/2005 | Linux kernel Bluetooth support fails to properly bounds check "protocol" variable |
| 8.32 | VU#218395 | 04/15/2008 | CUPS integer overflow vulnerability |
| 7.65 | VU#773720 | 05/14/2007 | Samba NDR MS-RPC heap buffer overflow |
| 7.59 | VU#22091 | 03/22/2000 | gpm-root fails to correctly release GID 0 membership for user defined menus |
| 7.48 | VU#698302 | 11/22/2004 | nfs-utils vulnerable to buffer overflow in "getquotainfo()" in "rquota_server.c" |
| 7.43 | VU#268336 | 05/14/2007 | Samba command injection vulnerability |
| 7.2 | VU#925211 | 05/13/2008 | Debian and Ubuntu OpenSSL packages contain a predictable random number generator |
| 7.03 | VU#527736 | 04/11/2001 | mkpasswd uses weak random number generator |
| 6.91 | VU#580124 | 07/26/2006 | MIT Kerberos (krb5) krshd and v4rcp do not properly validate setuid() or seteuid() calls |
| 6.73 | VU#686403 | 08/31/2000 | ld.so fails to unset LD_PRELOAD before executing suid root programs |
| 5.85 | VU#349019 | 07/09/2001 | Tripwire vulnerable to arbitrary file overwriting via symlink redirection of temporary file |
| 5.73 | VU#184030 | 07/01/2004 | MySQL fails to properly evaluate zero-length strings in the check_scramble_323() function |
| 5.73 | VU#230307 | 02/25/2002 | Linux kernel netfilter IRC DCC helper module creates overly permissive firewall rules |
| 5.73 | VU#327560 | 09/04/2004 | Mozilla "send page" feature contains a buffer overflow vulnerability |
| 5.4 | VU#964488 | 01/10/2001 | ISC inn creates temporary files insecurely |
| 4.5 | VU#579928 | 01/10/2001 | diffutils sdiff creates temporary files insecurely |
| 4.35 | VU#856689 | 12/21/2005 | VMware NAT Service vulnerable to buffer overflow via FTP PORT/EPRT commands |
| 4.3 | VU#995038 | 12/23/2004 | Debian Linux Netkit telnetd-ssl contains a format string vulnerability |
| 3.71 | VU#920689 | 03/12/2007 | Linux Kernel vulnerable to DoS via the ipv6_getsockopt_sticky() function |
| 3.64 | VU#428500 | 12/19/2006 | Mozilla LiveConnect vulnerable to crash finalizing JS objects |
| 3.64 | VU#447772 | 12/19/2006 | Mozilla JavaScript Engine multiple memory corruption vulnerabilities |
| 3.37 | VU#481998 | 09/15/2004 | Apache vulnerable to buffer overflow when expanding environment variables |
| 3.37 | VU#797027 | 06/19/2001 | OpenSSH does not initialize PAM session thereby allowing PAM restrictions to be bypassed |
| 3.37 | VU#925529 | 12/07/2006 | Madwifi wireless driver buffer overflow vulnerability |
| 3.24 | VU#129910 | 10/22/2004 | SuSe Linux LibTIFF package vulnerable to buffer overflow |
| 3.15 | VU#898480 | 11/20/2001 | MandrakeSoft Mandrake Linux Apache default configuration sample programs disclose server information |
| 3.03 | VU#25701 | 07/27/2000 | Linux gpm daemon allows arbitrary file removal |
| 3.03 | VU#35842 | 07/03/2000 | man 'makewhatis' insecurely uses /tmp |
| 3 | VU#610904 | 12/22/2000 | Oracle Internet Directory LDAP Daemon does not check write permissions properly |
| 2.95 | VU#337238 | 01/16/2004 | Red Hat Enterprise Linux kernel-2.4.21 does not perform adequate checking of eflags when in 32-bit ptrace emulation mode |
| 2.69 | VU#681569 | 05/23/2006 | Linux Kernel may fail to properly handle SNMP packets |
| 2.65 | VU#426456 | 01/10/2001 | gpm creates temporary files insecurely |
| 2.64 | VU#24140 | 03/27/2000 | Linux kernel IP Masquerading "destination loose" (DLOOSE) configuration passes arbitrary UDP traffic |
| 2.23 | VU#645326 | 07/01/2004 | MySQL fails to properly handle overly long "scramble" values |
| 1.82 | VU#249579 | 02/10/2001 | klogd does not adequately handle NULL byte when parsing text using LogLine( ) |
| 1.39 | VU#801526 | 02/03/2004 | util-linux login program discloses sensitive information |
| 1.36 | VU#471084 | 06/09/2003 | Linux kernel IP stack incorrectly calculates size of an ICMP citation for ICMP errors |
| 1.35 | VU#723910 | 03/31/2004 | MPlayer contains a buffer overflow in the HTTP parser |
| 1.35 | VU#970849 | 07/12/2007 | libarchive does not properly terminate loop |
| 1.28 | VU#523888 | 02/17/2005 | Gaim vulnerable to HTML processing denial of service |
| 1.28 | VU#795812 | 02/28/2005 | Gaim vulnerable to DoS via specially crafted HTML |
| 1.28 | VU#839280 | 02/17/2005 | Gaim vulnerable to malformed SNAC packet infinite processing loop |
| 1.06 | VU#726198 | 11/17/2004 | SMB filesystem read system call vulnerable to buffer overflow |
| 1.06 | VU#296681 | 12/06/2006 | Intel network drivers privilege escalation vulnerability |
| 1.02 | VU#253024 | 12/14/2004 | Adobe Acrobat Reader for UNIX contains a buffer overflow in mailListIsPdf() |
| 0.91 | VU#512193 | 11/20/2007 | IBM Director fails to properly time-out connection requests from clients |
| 0.63 | VU#110297 | 04/12/2007 | Flash Player information disclosure vulnerability |
| 0.63 | VU#377544 | 09/04/2007 | MIT Kerberos 5 kadmind privilege escalation vulnerability |
| 0.48 | VU#981134 | 08/25/2004 | Linux kernel USB drivers do not initialize kernel memory properly |
| 0.3 | VU#424080 | 01/10/2001 | shadow-utils useradd creates temporary files insecurely |
| 0.23 | VU#312692 | 05/31/2006 | Shadow Utils useradd utility sets incorrect file permissions |
| 0.21 | VU#913704 | 11/20/2001 | MandrakeSoft Mandrake Linux Apache default configuration enables directory indexing |
| 0.21 | VU#927256 | 11/20/2001 | MandrakeSoft Mandrake Linux Apache default configuration enables Perl ProxyPass server on 8200/tcp |
| 0.18 | VU#455323 | 06/17/2002 | Mandrake Security may make unexpected system modifications |
| 0.1 | VU#110803 | 05/23/2001 | CrushFTP Server does not adequately filter user input thereby permitting directory traversal |
| 0.1 | VU#664141 | 09/26/2000 | Debian glibc 2 symlink issue could allow arbitrary file overwriting |
| 0.06 | VU#300368 | 08/29/2006 | X.Org fails to check for setuid failure on Linux systems |
| 0.03 | VU#245984 | 10/19/2006 | The Red Hat Enterprise Linux 3 SMP Kernel fails to properly handle IPC shared-memory |
| 0 | VU#34043 | 07/16/2000 | rpc.statd vulnerable to remote root compromise via format string stack overwrite |
| 0 | VU#493966 | 02/12/2004 | Libxml2 URI parsing errors in nanohttp and nanoftp |
| 0 | VU#717844 | 07/12/2006 | Linux kernel fails to properly handle malformed SCTP packets |
If this page is empty, your search did not match any documents.