Skip to content
Noroxi

openpkg records

27 published records for vendor openpkg.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 3.7%
Pre-auth RCE
15
With a fix record
88.9%
Median publish → KEV
No record has entered KEV

All records

27 records
  • Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of ser

    CriticalCVSS 10.0Proof of conceptEPSS 28%

    gd graphics library · gdlibMar 1, 2005

  • Buffer overflow in the UUDeview package, as used in WinZip 6.2 through WinZip 8.1 SR-1, and possibly other packages, allows remote attackers

    CriticalCVSS 10.0Proof of conceptEPSS 24%

    uudeview · uudeviewNov 23, 2004

  • Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attacker

    CriticalCVSS 10.0Proof of conceptEPSS 13%

    cvs · cvsAug 6, 2004

  • OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which

    MediumCVSS 5.0WeaponizedEPSS 77%

    openbsd · opensshMay 12, 2003

  • Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.

    CriticalCVSS 9.8Proof of conceptEPSS 15%

    immunix · immunixMar 15, 2002

  • Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary cod

    CriticalCVSS 10.0No exploitEPSS 10%

    php · phpJan 10, 2005

  • The deserialization code in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to cause a denial of service and execute arbit

    CriticalCVSS 10.0No exploitEPSS 8%

    php · phpJan 10, 2005

  • The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary cod

    CriticalCVSS 10.0No exploitEPSS 6%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • libsvn_ra_svn in Subversion 1.0.4 trusts the length field of (1) svn://, (2) svn+ssh://, and (3) other svn protocol URL strings, which allow

    CriticalCVSS 10.0No exploitEPSS 6%

    subversion · subversionAug 6, 2004

  • Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to exec

    CriticalCVSS 10.0No exploitEPSS 6%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary cod

    CriticalCVSS 10.0No exploitEPSS 6%

    carnegie mellon university · cyrus imap serverJan 10, 2005

  • serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote att

    CriticalCVSS 10.0No exploitEPSS 6%

    cvs · cvsAug 6, 2004

  • Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to exec

    CriticalCVSS 9.8No exploitEPSS 7%

    mit · kerberos 5Oct 20, 2004

  • CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator fr

    CriticalCVSS 10.0No exploitEPSS 4%

    cvs · cvsAug 6, 2004

  • CVE-2004-0594
    36Monitor

    The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is ena

    MediumCVSS 5.1Proof of conceptEPSS 55%

    hp · hp-uxJul 27, 2004

  • CVE-2004-0940
    32Monitor

    Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute

    HighCVSS 7.8Proof of conceptEPSS 5%

    apache · http serverFeb 9, 2005

  • CVE-2007-5116
    31Monitor

    Buffer overflow in the polymorphic opcode support in the Regular Expression Engine (regcomp.c) in Perl 5.8 allows context-dependent attacker

    HighCVSS 7.5No exploitEPSS 5%

    debian · debian linuxNov 7, 2007

  • CVE-2005-0373
    31Monitor

    Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL bu

    HighCVSS 7.5No exploitEPSS 4%

    cyrus · saslOct 7, 2004

  • CVE-2002-0985
    31Monitor

    Argument injection vulnerability in the mail function for PHP 4.x to 4.2.2 may allow attackers to bypass safe mode restrictions and modify c

    HighCVSS 7.5No exploitEPSS 3%

    php · phpSep 24, 2002

  • CVE-2004-1471
    30Monitor

    Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commi

    HighCVSS 7.1Proof of conceptEPSS 8%

    cvs · cvsDec 31, 2004

  • CVE-2004-0957
    28Monitor

    Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore),

    MediumCVSS 6.8No exploitEPSS 2%

    openpkg · openpkgFeb 9, 2005

  • CVE-2004-0918
    25Monitor

    The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de

    MediumCVSS 5.0No exploitEPSS 16%

    squid · squidJan 27, 2005

  • CVE-2003-0147
    22Monitor

    OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining fact

    MediumCVSS 5.0No exploitEPSS 6%

    openssl · opensslMar 31, 2003

  • CVE-2004-0421
    21Monitor

    The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG

    MediumCVSS 5.0No exploitEPSS 4%

    libpng · libpngAug 18, 2004

  • CVE-2004-0417
    21Monitor

    Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may

    MediumCVSS 5.0No exploitEPSS 3%

    cvs · cvsAug 6, 2004