Vulnerabilities > Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-04-24 CVE-2007-2191 HTML Injection vulnerability in Freepbx 2.2.1/2.2Rc1
Multiple cross-site scripting (XSS) vulnerabilities in freePBX 2.2.x allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, (3) Call-ID, (4) User-Agent, and unspecified other SIP protocol fields, which are stored in /var/log/asterisk/full and displayed by admin/modules/logfiles/asterisk-full-log.php.
6.8
2007-04-06 CVE-2007-1884 Format String vulnerability in PHP Printf() Function 64bit Casting
Multiple integer signedness errors in the printf function family in PHP 4 before 4.4.5 and PHP 5 before 5.2.1 on 64 bit machines allow context-dependent attackers to execute arbitrary code via (1) certain negative argument numbers that arise in the php_formatted_print function because of 64 to 32 bit truncation, and bypass a check for the maximum allowable value; and (2) a width and precision of -1, which make it possible for the php_sprintf_appendstring function to place an internal buffer at an arbitrary memory location.
6.8
2007-03-28 CVE-2007-1730 Local Information Disclosure vulnerability in Linux Kernel 2.6.20/2.6.20.1/2.6.20.2
Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value.
local
low complexity
linux
6.6
2007-03-28 CVE-2007-1727 Remote Unauthorized Access vulnerability in HP OpenView Network Node Manager
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.
network
low complexity
hp linux microsoft sun
6.5
2007-03-20 CVE-2006-7164 Information Disclosure vulnerability in Websphere Application Server
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.
network
linux unix ibm
4.3
2007-03-16 CVE-2007-1497 Unspecified vulnerability in Linux Kernel
nf_conntrack in netfilter in the Linux kernel before 2.6.20.3 does not set nfctinfo during reassembly of fragmented packets, which leaves the default value as IP_CT_ESTABLISHED and might allow remote attackers to bypass certain rulesets using IPv6 fragments.
network
low complexity
linux
5.0
2007-03-16 CVE-2007-1496 NULL Pointer Dereference vulnerability in Linux Kernel Netfilter NFNetLink_Log
nfnetlink_log in netfilter in the Linux kernel before 2.6.20.3 allows attackers to cause a denial of service (crash) via unspecified vectors involving the (1) nfulnl_recv_config function, (2) using "multiple packets per netlink message", and (3) bridged packets, which trigger a NULL pointer dereference.
local
low complexity
linux
4.9
2007-03-10 CVE-2007-1388 Resource Management Errors vulnerability in Linux Kernel
The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option length or invalid option value, which triggers a NULL pointer dereference.
local
linux CWE-399
4.4
2007-03-10 CVE-2007-0005 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Omnikey.Aaitg Omnikey Cardman 4040
Multiple buffer overflows in the (1) read and (2) write handlers in the Omnikey CardMan 4040 driver in the Linux kernel before 2.6.21-rc3 allow local users to gain privileges.
6.9
2007-03-02 CVE-2007-1217 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Linux Kernel
Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a denial of service (crash) and possibly gain privileges via a crafted CAPI packet.
local
linux CWE-119
6.9