Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0022 Remote Buffer Overflow vulnerability in University of Cambridge Exim 4.41/4.42
Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.
local
low complexity
university-of-cambridge
4.6
2005-05-02 CVE-2005-0021 Unspecified vulnerability in University of Cambridge Exim 4.41/4.42
Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.
local
low complexity
university-of-cambridge
7.2
2005-05-02 CVE-2005-0018 Local Insecure Temporary File Creation vulnerability in F2C Open Source Project F2C Translator 3.1
The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
local
low complexity
f2c-open-source-project
2.1
2005-05-02 CVE-2005-0017 Local Insecure Temporary File Creation vulnerability in F2C
The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
local
low complexity
f2c-open-source-project
2.1
2005-05-02 CVE-2005-0015 Unspecified vulnerability in Crosswire Bible Society Sword 1.5.7A
diatheke.pl in Sword 1.5.7a allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
network
low complexity
crosswire-bible-society
7.5
2005-05-02 CVE-2005-0014 Remote vulnerability in NCPFS
Buffer overflow in ncplogin in ncpfs before 2.2.6 allows remote malicious NetWare servers to execute arbitrary code on the NetWare client.
network
low complexity
ncpfs
7.5
2005-05-02 CVE-2005-0013 Remote vulnerability in NCPFS
nwclient.c in ncpfs before 2.2.6 does not drop root privileges before executing utilities using the NetWare client functions, which allows local users to gain privileges.
local
low complexity
ncpfs
7.2
2005-05-02 CVE-2005-0012 Unspecified vulnerability in Dillo web Browser
Format string vulnerability in the a_Interface_msg function in Dillo before 0.8.3-r4 allows remote attackers to execute arbitrary code via format string specifiers in a web page.
network
low complexity
dillo
7.5
2005-05-02 CVE-2005-0011 Unspecified vulnerability in KDE 3.3/3.3.1/3.3.2
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remote attackers to execute arbitrary code via stack-based buffer overflows.
network
low complexity
kde
critical
10.0
2005-05-02 CVE-2005-0005 Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
network
low complexity
graphicsmagick imagemagick sgi debian gentoo suse
7.5