Search CVE reports


Toggle filters

441 – 450 of 490 results


CVE-2007-6465

Low priority
Not affected

Multiple cross-site scripting (XSS) vulnerabilities in ganglia-web in Ganglia before 3.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) c and (2) h parameters to (a) web/host_gmetrics.php; the (3) G,...

1 affected package

ganglia-monitor-core

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ganglia-monitor-core
Show less packages

CVE-2007-5393

Medium priority

Some fixes available 25 of 36

Heap-based buffer overflow in the CCITTFaxStream::lookChar method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a PDF file that contains a crafted CCITTFaxDecode filter.

13 affected packages

cups, cupsys, gpdf, ipe, kdegraphics...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
cupsys
gpdf
ipe
kdegraphics
koffice
libextractor
pdfkit.framework
pdftohtml
poppler
tetex-bin
texlive-bin
xpdf
Show all 13 packages Show less packages

CVE-2007-5392

Medium priority

Some fixes available 25 of 36

Integer overflow in the DCTStream::reset method in xpdf/Stream.cc in Xpdf 3.02p11 allows remote attackers to execute arbitrary code via a crafted PDF file, resulting in a heap-based buffer overflow.

13 affected packages

cups, cupsys, gpdf, ipe, kdegraphics...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cups
cupsys
gpdf
ipe
kdegraphics
koffice
libextractor
pdfkit.framework
pdftohtml
poppler
tetex-bin
texlive-bin
xpdf
Show all 13 packages Show less packages

CVE-2007-4352

Medium priority

Some fixes available 25 of 36

Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and...

13 affected packages

gpdf, cups, ipe, cupsys, kdegraphics...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gpdf
cups
ipe
cupsys
kdegraphics
koffice
libextractor
pdfkit.framework
pdftohtml
poppler
tetex-bin
texlive-bin
xpdf
Show all 13 packages Show less packages

CVE-2007-4174

Low priority
Ignored

Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify the torrc configuration file, compromise anonymity, and have other unspecified...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2007-4099

Medium priority

Some fixes available 3 of 6

Tor before 0.1.2.15 can select a guard node beyond the first listed never-before-connected-to guard node, which allows remote attackers with control of certain guard nodes to obtain sensitive information and possibly leverage...

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2007-4098

Medium priority

Some fixes available 3 of 6

Tor before 0.1.2.15 does not properly distinguish "streamids from different exits," which might allow remote attackers with control over Tor routers to inject cells into arbitrary streams.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2007-4097

Medium priority

Some fixes available 3 of 6

Tor before 0.1.2.15 sends "destroy cells" containing the reason for tearing down a circuit, which allows remote attackers to obtain sensitive information, contrary to specifications.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2007-4096

Medium priority

Some fixes available 3 of 6

Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages

CVE-2007-3165

Medium priority
Ignored

Tor before 0.1.2.14 can construct circuits in which an entry guard is in the same family as the exit node, which might compromise the anonymity of traffic sources and destinations by exposing traffic to inappropriate remote observers.

1 affected package

tor

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tor
Show less packages