Vulnerabilities > Conectiva > Medium

DATE CVE VULNERABILITY TITLE RISK
2004-09-13 CVE-2004-0807 Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.
network
low complexity
samba sgi conectiva mandrakesoft suse
5.0
2003-08-27 CVE-2003-0540 Denial of Service vulnerability in Multiple Postfix
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.
network
low complexity
wietse-venema conectiva
5.0
2003-08-27 CVE-2003-0468 Denial of Service vulnerability in Multiple Postfix
Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.
network
low complexity
wietse-venema conectiva
5.0
2001-12-06 CVE-2001-0834 Remote Denial of Service/File Disclosure vulnerability in ht://Dig
htsearch CGI program in htdig (ht://Dig) 3.1.5 and earlier allows remote attackers to use the -c option to specify an alternate configuration file, which could be used to (1) cause a denial of service (CPU consumption) by specifying a large file such as /dev/zero, or (2) read arbitrary files by uploading an alternate configuration file that specifies the target file.
network
low complexity
htdig conectiva debian suse
6.4
2001-07-19 CVE-2001-1375 tcl/tk package (tcltk) 8.3.1 searches for its libraries in the current working directory before other directories, which could allow local users to execute arbitrary code via a Trojan horse library that is under a user-controlled directory.
local
low complexity
conectiva redhat
4.6
2000-07-27 CVE-2000-0668 pam_console PAM module in Linux systems allows a user to access the system console and reboot the system when a display manager such as gdm or kdm has XDMCP enabled.
network
low complexity
michael-k-johnson conectiva redhat
5.0