Vulnerabilities > Redhat > Enterprise Linux > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-04-14 CVE-2004-1090 Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header." 5.0
2005-04-14 CVE-2004-1009 Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors. 5.0
2005-03-15 CVE-2005-0384 Remote Denial Of Service vulnerability in Linux Kernel PPP Driver
Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.
network
low complexity
redhat suse trustix ubuntu
5.0
2005-03-14 CVE-2005-0473 Remote Denial of Service vulnerability in Gaim
The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.
network
low complexity
rob-flynn mandrakesoft redhat
5.0
2005-03-14 CVE-2005-0472 Remote Denial of Service vulnerability in Gaim
Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.
network
low complexity
rob-flynn mandrakesoft redhat
5.0
2005-03-14 CVE-2005-0398 Denial of Service vulnerability in KAME Racoon Malformed ISAKMP Packet Headers
The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.
network
low complexity
ipsec-tools kame sgi altlinux redhat suse
5.0
2005-03-07 CVE-2005-0667 Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.
network
high complexity
sylpheed sylpheed-claws altlinux gentoo redhat
5.1
2005-03-05 CVE-2005-0109 Information Disclosure vulnerability in Multiple Vendor Hyper-Threading Technology
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
4.7
2005-02-09 CVE-2004-0961 Attribute Decoding Denial Of Service vulnerability in FreeRADIUS
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
network
low complexity
freeradius redhat
5.0
2005-02-09 CVE-2004-0960 Attribute Decoding Denial Of Service vulnerability in FreeRADIUS
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
network
low complexity
freeradius redhat
5.0