SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Search Results

MetricIDDate
Public
Name
108.16VU#1653211/10/1999BIND T_NXT record processing may cause buffer overflow
87.72VU#2982306/23/2000Format string input validation error in wu-ftpd site_exec() function
48.19VU#38236509/25/2000LPRng can pass user-supplied input as a format string parameter to syslog() calls
38.95VU#13702401/16/2001Compaq web-enabled management software contains buffer overflow in authentication username
38.9VU#57218301/29/2001ISC BIND 4 contains buffer overflow in nslookupComplain()
33.07VU#71597311/07/2000ISC BIND 8.2.2-P6 vulnerable to DoS via compressed zone transfer, aka the "zxfr bug"
24.84VU#16984110/15/2002dvips uses system() function insecurely thereby allowing arbitrary command execution
21.93VU#40305105/29/2001GnuPG format string vulnerability in do_get() in ttyio.c while prompting for a new filename
21.37VU#36881903/11/2002Double Free Bug in zlib Compression Library Corrupts malloc's Internal Data Structures
21.37VU#79826309/08/2001Taylor UUCP Package fails to properly filter command line arguments
18VU#75761205/28/2003Apache Portable Runtime contains heap buffer overflow in apr_psprintf()
17.1VU#59242502/02/2006Mozilla-based products fail to validate user input to the attribute name in "XULDocument.persist"
16.49VU#60077709/26/2002gv contains buffer overflow in sscanf() function
15.82VU#13402502/07/2003kernel-utils sets insecure permissions on "uml_net" utility
14.06VU#3900101/08/2000lpd allows options to be passed to sendmail
13.35VU#67056804/23/2001Samba creates temporary files insecurely
12.6VU#29192403/28/2005Multiple Telnet clients fail to properly handle the "LINEMODE" SLC suboption
12.57VU#36118109/26/2005Helix Player format string vulnerability
11.39VU#81419803/23/2003SSH Tectia Server contains a race condition when the password change plugin is enabled
11.22VU#27597910/01/2001Compaq web-enabled management software buffer overflow vulnerability
9.81VU#99124003/22/2001Compaq web-enabled management software acts as generic proxy
9.61VU#70497611/22/2000Aladdin Ghostscript LD_RUN_PATH environment variable allows libraries to be loaded from current directory
9.44VU#68062007/02/2005zlib inflate() routine vulnerable to buffer overflow
9.44VU#85309705/18/2009ntpd autokey stack buffer overflow
9.21VU#69864002/08/2001Linux kernel does not properly validate user input via sysctl for negative value
9.11VU#68491306/20/2005Ruby library contains vulnerable default value
8.85VU#1314511/10/1999BIND memcpy not bounded in case T_SIG of rrextract()
8.85VU#36935809/15/2004GdkPixbuf XPM parser contains a stack overflow vulnerability
8.85VU#72989409/15/2004GdkPixbuf XPM parser contains a heap overflow vulnerability
8.82VU#78744809/27/2006OpenSSH fails to properly handle multiple identical blocks in a SSH packet
8.43VU#68026008/26/2003pam_smb module contains remote buffer overflow
8.1VU#82079801/14/2004KDE Personal Information Management suite "kdepim" contains a buffer overflow vulnerability in VCF information reader
8.08VU#51878207/06/2004Ethereal fails to properly handle malformed SMB packets
8.08VU#82942207/06/2004Ethereal fails to properly handle malformed iSNS packets
8.08VU#83584607/06/2004Ethereal fails to properly handle malfored SNMP packets
7.87VU#3030801/08/2000lpd hostname authentication bypassed with spoofed DNS
7.59VU#2209103/22/2000gpm-root fails to correctly release GID 0 membership for user defined menus
7.42VU#10244109/12/2005Multiple X servers fail to properly allocate memory for large pixmaps
7.03VU#52773604/11/2001mkpasswd uses weak random number generator
5.73VU#23030702/25/2002Linux kernel netfilter IRC DCC helper module creates overly permissive firewall rules
5.01VU#19661704/16/2009Xpdf and poppler contain multiple vulnerabilities in the processing of JBIG2 data
4.86VU#23056102/24/2003gnome-terminal allows arbitrary command execution when viewing files containing crafted escape sequences
4.5VU#57992801/10/2001diffutils sdiff creates temporary files insecurely
4.32VU#57095212/20/2000Redhat Linux diskcheck.pl creates predictable temporary file and fails to check for existing symbolic link of same name
3.75VU#89117710/01/2002PostgreSQL VACUUM command allows unprivileged user to remove database transaction log data
3.37VU#40180804/15/2001exuberant-ctags creates temporary files insecurely
3.37VU#48199809/15/2004Apache vulnerable to buffer overflow when expanding environment variables
3.03VU#2570107/27/2000Linux gpm daemon allows arbitrary file removal
3.03VU#3584207/03/2000man 'makewhatis' insecurely uses /tmp
2.95VU#17408601/14/2004tcpdump contains vulnerability in ISAKMP decoding function rawprint() in print-isakmp.c
2.95VU#33723801/16/2004Red Hat Enterprise Linux kernel-2.4.21 does not perform adequate checking of eflags when in 32-bit ptrace emulation mode
2.95VU#73851801/14/2004tcpdump contains vulnerability in ISAKMP decoding routine
2.95VU#95552601/14/2004tcpdump contains vulnerability in RADIUS decoding function print_attr_string() in print-radius.c
2.7VU#56102205/29/2004Mozilla contains a buffer overflow in the SendUidl() function
1.77VU#57765409/15/2004GdkPixbuf ICO parser contains an integer overflow vulnerability
1.77VU#82537409/15/2004GdkPixbuf BMP parser may enter an infinite loop
1.65VU#85134009/29/2006OpenSSH contains a race condition vulnerability
1.62VU#60670003/19/2007file integer overflow vulnerability
1.44VU#74492908/31/2005mod_ssl fails to properly enforce client certificates authentication
1.39VU#80152602/03/2004util-linux login program discloses sensitive information
1.26VU#35640902/11/2005mod_python vulnerable to information disclosure via crafted URL
1.12VU#39627201/10/2001mgetty creates temporary files insecurely
0.96VU#81455705/24/2005GNOME gedit contains format string vulnerability
0.63VU#11029704/12/2007Flash Player information disclosure vulnerability
0.23VU#31269205/31/2006Shadow Utils useradd utility sets incorrect file permissions
0.21VU#62691911/13/2000Race condition in periodic
0.05VU#24368106/29/2006OpenOffice.org may fail to properly contain certain Java applets
0.03VU#24598410/19/2006The Red Hat Enterprise Linux 3 SMP Kernel fails to properly handle IPC shared-memory
0VU#12054111/05/2009SSL and TLS protocols renegotiation vulnerability
0VU#3404307/16/2000rpc.statd vulnerable to remote root compromise via format string stack overwrite

If this page is empty, your search did not match any documents.

Produced 2010 by US-CERT, a government organization
Disclaimers and copyright information