CVEs (27)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Larry Wall MandrakesoftOpenpkg+1 more4Enterprise Linux Mandrake Multi Network FirewallOpenpkg+1 moreApr 23, 2026 Nov 7, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attackers to execute arbitrary code by switching from byte to Unicode (UTF) characters i...Show more |
5Gd Graphics Library GentooOpenpkg+2 more5Gdlib LinuxOpenpkg+2 moreApr 16, 2026 Mar 1, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image ro...Show more |
6Openpkg OracleRedhat+3 more7Enterprise Linux Enterprise Linux DesktopMysql+4 moreApr 16, 2026 Feb 9, 2005 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow th...Show more |
6Apache HpOpenpkg+3 more6Hp Ux Http ServerOpenpkg+3 moreApr 16, 2026 Feb 9, 2005 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a lengt...Show more |
6Gentoo OpenpkgRedhat+3 more6Fedora Core LinuxOpenpkg+3 moreApr 16, 2026 Jan 27, 2005 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length f...Show more |
4Openpkg PhpTrustix+1 more4Openpkg PhpSecure Linux+1 moreApr 16, 2026 Jan 10, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file. |
4Openpkg PhpTrustix+1 more4Openpkg PhpSecure Linux+1 moreApr 16, 2026 Jan 10, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbitrary code via untrusted data to the unserialize function that may trigger "infor...Show more |
6Carnegie Mellon University ConectivaOpenpkg+3 more6Cyrus Imap Server Fedora CoreLinux+3 moreApr 16, 2026 Jan 10, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p")...Show more |
6Carnegie Mellon University ConectivaOpenpkg+3 more6Cyrus Imap Server Fedora CoreLinux+3 moreApr 16, 2026 Jan 10, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body...Show more |
6Carnegie Mellon University ConectivaOpenpkg+3 more6Cyrus Imap Server Fedora CoreLinux+3 moreApr 16, 2026 Jan 10, 2005 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulner...Show more |
6Cvs FreebsdGentoo+3 more6Cvs FreebsdLinux+3 moreApr 16, 2026 Dec 31, 2004 N/A· v4 N/A· v3 7.1 HIGH· v2 Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute a...Show more |
4Gentoo OpenpkgUudeview+1 more4Linux OpenpkgUudeview+1 moreApr 16, 2026 Nov 23, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers to execute arbitrary code via a MIME archive with certain long MIME parameters. |
3Debian MitOpenpkg3Debian Linux Kerberos 5OpenpkgApr 16, 2026 Oct 20, 2004 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code. |
6Apple ConectivaCyrus+3 more8Fedora Core LinuxMac Os X+5 moreApr 16, 2026 Oct 7, 2004 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary cod...Show more |
4Libpng OpenpkgRedhat+1 more6Enterprise Linux Enterprise Linux DesktopLibpng+3 moreApr 16, 2026 Aug 18, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creatin...Show more |
5Cvs GentooOpenbsd+2 more5Cvs LinuxOpenbsd+2 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrar...Show more |
5Cvs GentooOpenbsd+2 more5Cvs LinuxOpenbsd+2 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data...Show more |
5Cvs GentooOpenbsd+2 more5Cvs LinuxOpenbsd+2 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code. |
5Cvs GentooOpenbsd+2 more5Cvs LinuxOpenbsd+2 moreApr 16, 2026 Aug 6, 2004 N/A· v4 N/A· v3 10.0 HIGH· v2 CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of criti...Show more |
libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allows remote attackers to cause a denial of service (memory consumption) and possibl...Show more |