Skip to content
Noroxi

conectiva records

66 published records for vendor conectiva.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
22
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

66 records
  • CVE-2003-0780
    60This week

    Buffer overflow in get_salt_from_password from sql_acl.cc for MySQL 4.0.14 and earlier, and 3.23.x, allows attackers with ALTER TABLE privil

    CriticalCVSS 9.0Proof of conceptEPSS 78%

    mysql · mysqlSep 22, 2003

  • rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote at

    CriticalCVSS 10.0Proof of conceptEPSS 26%

    conectiva · linuxJul 16, 2000

  • Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers t

    CriticalCVSS 10.0Proof of conceptEPSS 25%

    sox · soxAug 6, 2004

  • Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attacke

    CriticalCVSS 10.0Proof of conceptEPSS 16%

    caldera · openlinux ebuilderNov 14, 2000

  • Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a

    CriticalCVSS 10.0No exploitEPSS 14%

    samba · sambaJan 27, 2005

  • Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.

    CriticalCVSS 9.8Proof of conceptEPSS 15%

    immunix · immunixMar 15, 2002

  • Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow r

    CriticalCVSS 10.0No exploitEPSS 10%

    mozilla · mozillaJan 27, 2005

  • Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.

    CriticalCVSS 10.0No exploitEPSS 10%

    mozilla · mozillaJan 27, 2005

  • The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly rest

    CriticalCVSS 9.3Proof of conceptEPSS 17%

    sun · jdkMar 1, 2005

  • Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.

    CriticalCVSS 10.0No exploitEPSS 8%

    mozilla · firefoxDec 31, 2004

  • The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary cod

    CriticalCVSS 10.0No exploitEPSS 6%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to exec

    CriticalCVSS 10.0No exploitEPSS 6%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary cod

    CriticalCVSS 10.0No exploitEPSS 6%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial

    CriticalCVSS 10.0No exploitEPSS 4%

    libextractor · libextractorDec 31, 2005

  • The logrotate script for OpenLDAP before 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.

    CriticalCVSS 10.0No exploitEPSS 2%

    conectiva · linuxOct 20, 2000

  • CVE-2001-0690
    34Monitor

    Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allows a remote attacker

    HighCVSS 7.5Proof of conceptEPSS 12%

    conectiva · linuxSep 20, 2001

  • CVE-2001-0136
    33Monitor

    Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE comman

    MediumCVSS 5.0Proof of conceptEPSS 45%

    proftpd · proftpdMar 12, 2001

  • CVE-2005-0699
    32Monitor

    Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and ea

    HighCVSS 7.5No exploitEPSS 6%

    ethereal group · etherealMar 8, 2005

  • CVE-2004-1307
    32Monitor

    Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code vi

    HighCVSS 7.5No exploitEPSS 6%

    libtiff · libtiffDec 21, 2004

  • CVE-2004-0827
    32Monitor

    Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a de

    HighCVSS 7.5No exploitEPSS 6%

    imagemagick · imagemagickSep 16, 2004

  • CVE-2004-0817
    31Monitor

    Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.

    HighCVSS 7.5No exploitEPSS 5%

    enlightenment · imlibDec 31, 2004

  • CVE-2001-0440
    31Monitor

    Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitra

    HighCVSS 7.5Proof of conceptEPSS 5%

    licq · licqJul 2, 2001

  • CVE-2004-0801
    31Monitor

    Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitra

    HighCVSS 7.5No exploitEPSS 4%

    linuxprinting.org · foomatic-filtersSep 16, 2004

  • CVE-2005-0373
    31Monitor

    Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bu

    HighCVSS 7.5No exploitEPSS 4%

    cyrus · saslOct 7, 2004

  • CVE-2005-0754
    31Monitor

    Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbi

    HighCVSS 7.5No exploitEPSS 3%

    kde · quantaApr 22, 2005