conectiva records
66 published records for vendor conectiva.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 22
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-399 Resource Management Errors2
- CWE-193 Off-by-one Error1
- CWE-20 Improper Input Validation1
- CWE-401 Missing Release of Memory after Effective Lifetime1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
The weakness classes this vendor ships most often: where to look.
CWEAll records
66 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2003-0780Proof of concept | Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privilmysql · mysql | Critical9.0 | — | 78.4% | Sep 22, 2003 |
48Plan | CVE-2000-0666Proof of concept | rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote atconectiva · linux | Critical10.0 | — | 26.3% | Jul 16, 2000 |
48Plan | CVE-2004-0557Proof of concept | Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers tsox · sox | Critical10.0 | — | 25.1% | Aug 6, 2004 |
45Plan | CVE-2000-0844Proof of concept | Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackecaldera · openlinux ebuilder · CWE-264 | Critical10.0 | — | 15.6% | Nov 14, 2000 |
44Plan | CVE-2004-0882No exploit | Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via asamba · samba | Critical10.0 | — | 13.7% | Jan 27, 2005 |
43Plan | CVE-2002-0083Proof of concept | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.immunix · immunix · CWE-193 | Critical9.8 | — | 14.7% | Mar 15, 2002 |
43Plan | CVE-2004-0902No exploit | Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow rmozilla · mozilla | Critical10.0 | — | 10.1% | Jan 27, 2005 |
43Plan | CVE-2004-0903No exploit | Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.mozilla · mozilla | Critical10.0 | — | 9.7% | Jan 27, 2005 |
42Plan | CVE-2004-1029Proof of concept | The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restsun · jdk · CWE-264 | Critical9.3 | — | 17.0% | Mar 1, 2005 |
42Plan | CVE-2004-0904No exploit | Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.mozilla · firefox | Critical10.0 | — | 8.0% | Dec 31, 2004 |
42Plan | CVE-2004-1012No exploit | The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Critical10.0 | — | 6.0% | Jan 10, 2005 |
42Plan | CVE-2004-1011No exploit | Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execcarnegie mellon university · cyrus imap server | Critical10.0 | — | 5.8% | Jan 10, 2005 |
42Plan | CVE-2004-1013No exploit | The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary codcarnegie mellon university · cyrus imap server | Critical10.0 | — | 5.8% | Jan 10, 2005 |
41Plan | CVE-2005-3625No exploit | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial libextractor · libextractor · CWE-399 | Critical10.0 | — | 3.8% | Dec 31, 2005 |
41Plan | CVE-2000-0747No exploit | The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.conectiva · linux | Critical10.0 | — | 1.7% | Oct 20, 2000 |
34Monitor | CVE-2001-0690Proof of concept | Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attackerconectiva · linux | High7.5 | — | 11.9% | Sep 20, 2001 |
33Monitor | CVE-2001-0136Proof of concept | Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commanproftpd · proftpd · CWE-401 | Medium5.0 | — | 44.9% | Mar 12, 2001 |
32Monitor | CVE-2005-0699No exploit | Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and eaethereal group · ethereal | High7.5 | — | 6.5% | Mar 8, 2005 |
32Monitor | CVE-2004-1307No exploit | Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code vilibtiff · libtiff | High7.5 | — | 6.3% | Dec 21, 2004 |
32Monitor | CVE-2004-0827No exploit | Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a deimagemagick · imagemagick | High7.5 | — | 5.5% | Sep 16, 2004 |
31Monitor | CVE-2004-0817No exploit | Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.enlightenment · imlib | High7.5 | — | 4.9% | Dec 31, 2004 |
31Monitor | CVE-2001-0440Proof of concept | Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitralicq · licq | High7.5 | — | 4.6% | Jul 2, 2001 |
31Monitor | CVE-2004-0801No exploit | Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitralinuxprinting.org · foomatic-filters | High7.5 | — | 4.3% | Sep 16, 2004 |
31Monitor | CVE-2005-0373No exploit | Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bucyrus · sasl | High7.5 | — | 3.9% | Oct 7, 2004 |
31Monitor | CVE-2005-0754No exploit | Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbikde · quanta | High7.5 | — | 3.0% | Apr 22, 2005 |
- CVE-2003-078060This week
Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privil
CriticalCVSS 9.0Proof of conceptEPSS 78%mysql · mysqlSep 22, 2003
- CVE-2000-066648Plan
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote at
CriticalCVSS 10.0Proof of conceptEPSS 26%conectiva · linuxJul 16, 2000
- CVE-2004-055748Plan
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers t
CriticalCVSS 10.0Proof of conceptEPSS 25%sox · soxAug 6, 2004
- CVE-2000-084445Plan
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attacke
CriticalCVSS 10.0Proof of conceptEPSS 16%caldera · openlinux ebuilderNov 14, 2000
- CVE-2004-088244Plan
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a
CriticalCVSS 10.0No exploitEPSS 14%samba · sambaJan 27, 2005
- CVE-2002-008343Plan
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
CriticalCVSS 9.8Proof of conceptEPSS 15%immunix · immunixMar 15, 2002
- CVE-2004-090243Plan
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow r
CriticalCVSS 10.0No exploitEPSS 10%mozilla · mozillaJan 27, 2005
- CVE-2004-090343Plan
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.
CriticalCVSS 10.0No exploitEPSS 10%mozilla · mozillaJan 27, 2005
- CVE-2004-102942Plan
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly rest
CriticalCVSS 9.3Proof of conceptEPSS 17%sun · jdkMar 1, 2005
- CVE-2004-090442Plan
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.
CriticalCVSS 10.0No exploitEPSS 8%mozilla · firefoxDec 31, 2004
- CVE-2004-101242Plan
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary cod
CriticalCVSS 10.0No exploitEPSS 6%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2004-101142Plan
Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to exec
CriticalCVSS 10.0No exploitEPSS 6%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2004-101342Plan
The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary cod
CriticalCVSS 10.0No exploitEPSS 6%carnegie mellon university · cyrus imap serverJan 10, 2005
- CVE-2005-362541Plan
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial
CriticalCVSS 10.0No exploitEPSS 4%libextractor · libextractorDec 31, 2005
- CVE-2000-074741Plan
The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.
CriticalCVSS 10.0No exploitEPSS 2%conectiva · linuxOct 20, 2000
- CVE-2001-069034Monitor
Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker
HighCVSS 7.5Proof of conceptEPSS 12%conectiva · linuxSep 20, 2001
- CVE-2001-013633Monitor
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE comman
MediumCVSS 5.0Proof of conceptEPSS 45%proftpd · proftpdMar 12, 2001
- CVE-2005-069932Monitor
Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and ea
HighCVSS 7.5No exploitEPSS 6%ethereal group · etherealMar 8, 2005
- CVE-2004-130732Monitor
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code vi
HighCVSS 7.5No exploitEPSS 6%libtiff · libtiffDec 21, 2004
- CVE-2004-082732Monitor
Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a de
HighCVSS 7.5No exploitEPSS 6%imagemagick · imagemagickSep 16, 2004
- CVE-2004-081731Monitor
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.
HighCVSS 7.5No exploitEPSS 5%enlightenment · imlibDec 31, 2004
- CVE-2001-044031Monitor
Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitra
HighCVSS 7.5Proof of conceptEPSS 5%licq · licqJul 2, 2001
- CVE-2004-080131Monitor
Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitra
HighCVSS 7.5No exploitEPSS 4%linuxprinting.org · foomatic-filtersSep 16, 2004
- CVE-2005-037331Monitor
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bu
HighCVSS 7.5No exploitEPSS 4%cyrus · saslOct 7, 2004
- CVE-2005-075431Monitor
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbi
HighCVSS 7.5No exploitEPSS 3%kde · quantaApr 22, 2005