Vulnerabilities > Linux > Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2012-12-03 CVE-2012-5611 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, allows remote authenticated users to execute arbitrary code via a long argument to the GRANT FILE command.
network
low complexity
mariadb oracle linux CWE-119
6.5
2010-07-02 CVE-2010-2594 Cross-Site Request Forgery (CSRF) vulnerability in Intersect Alliance Snare Agent and Snare Epilog
Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in InterSect Alliance Snare Agent 3.2.3 and earlier on Solaris, Snare Agent 3.1.7 and earlier on Windows, Snare Agent 1.5.0 and earlier on Linux and AIX, Snare Agent 1.4 and earlier on IRIX, Snare Epilog 1.5.3 and earlier on Windows, and Snare Epilog 1.2 and earlier on UNIX allow remote attackers to hijack the authentication of administrators for requests that (1) change the password or (2) change the listening port.
6.8
2010-05-14 CVE-2010-1556 Unauthorized Access vulnerability in HP Systems Insight Manager 5.3/6.0
Unspecified vulnerability in HP Systems Insight Manager (SIM) 5.3, 5.3 Update 1, and 6.0 allows remote attackers to obtain sensitive information and modify data via unknown vectors.
network
low complexity
hp linux microsoft
6.4
2009-11-02 CVE-2009-3733 Path Traversal vulnerability in VMWare Esx, Esxi and Server
Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
vmware linux CWE-22
5.0
2009-04-30 CVE-2009-1493 Resource Management Errors vulnerability in Adobe Reader 8.1.4/9.1
The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.
network
adobe linux CWE-399
6.8
2009-04-07 CVE-2008-6662 Improper Input Validation vulnerability in AVG Anti-Virus 7.5.51
AVG Anti-Virus for Linux 7.5.51, and possibly earlier, allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via a malformed UPX compressed file, which triggers memory corruption.
network
linux avg CWE-20
4.3
2009-04-07 CVE-2008-6661 Numeric Errors vulnerability in Bitdefender Antivirus
Multiple integer overflows in the scanning engine in Bitdefender for Linux 7.60825 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed (1) NeoLite and (2) ASProtect packed PE file.
network
low complexity
bitdefender linux CWE-189
5.0
2009-02-26 CVE-2009-0521 Information Exposure vulnerability in Adobe Flash Player FOR Linux
Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH.
local
low complexity
adobe linux CWE-200
4.6