Skip to main content

CWE archive

CWE-399 CVEs

Programmatic archive

2,694 CVEs tagged with CWE-399467 Critical, 830 High, 1,300 Medium, 97 Low, 0 Unrated.

CVE-2006-4145

Published Aug 21, 2006

The Universal Disk Format (UDF) filesystem driver in Linux kernel 2.6.17 and earlier allows local users to cause a denial of service (hang and crash) via certain operations involv…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3121

Published Aug 17, 2006

The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3122

Published Aug 9, 2006

The supersede_lease function in memory.c in ISC DHCP (dhcpd) server 2.0pl5 allows remote attackers to cause a denial of service (application crash) via a DHCPDISCOVER packet with…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3083

Published Aug 9, 2006

The (1) krshd and (2) v4rcp applications in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, when running on Linux and AIX, and (b) Heimdal 0.7.2 and earlier, do not c…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3840

Published Jul 27, 2006

The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Serv…

CVSS 5.0 · Medium

CVE-2006-3627

Published Jul 21, 2006

Unspecified vulnerability in the GSM BSSMAP dissector in Wireshark (aka Ethereal) 0.10.11 to 0.99.0 allows remote attackers to cause a denial of service (crash) via unspecified ve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3631

Published Jul 21, 2006

Unspecified vulnerability in the SSH dissector in Wireshark (aka Ethereal) 0.9.10 to 0.99.0 allows remote attackers to cause a denial of service (infinite loop) via unknown attack…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2936

Published Jul 10, 2006

The ftdi_sio driver (usb/serial/ftdi_sio.c) in Linux kernel 2.6.x up to 2.6.17, and possibly later versions, allows local users to cause a denial of service (memory consumption) b…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2006-2451

Published Jul 7, 2006

The suid_dumpable support in Linux kernel 2.6.13 up to versions before 2.6.17.4, and 2.6.16 before 2.6.16.24, allows a local user to cause a denial of service (disk consumption) a…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2934

Published Jun 30, 2006

SCTP conntrack (ip_conntrack_proto_sctp.c) in netfilter for Linux kernel 2.6.17 before 2.6.17.3 and 2.6.16 before 2.6.16.23 allows remote attackers to cause a denial of service (c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1470

Published Jun 27, 2006

OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-3068

Published Jun 19, 2006

IBM DB2 Universal Database (UDB) before 8.2 FixPak 12 allows remote attackers to cause a denial of service (application crash) by sending "incorrect information ... regarding the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1173

Published Jun 7, 2006

Sendmail before 8.13.7 allows remote attackers to cause a denial of service via deeply nested, malformed multipart MIME messages that exhaust the stack during the recursive mime8t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2276

Published May 10, 2006

bgpd in Quagga 0.98 and 0.99 before 20060504 allows local users to cause a denial of service (CPU consumption) via a certain sh ip bgp command entered in the telnet interface.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2093

Published Apr 29, 2006

Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-2069

Published Apr 27, 2006

The recursor in PowerDNS before 3.0.1 allows remote attackers to cause a denial of service (application crash) via malformed EDNS0 packets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1993

Published Apr 25, 2006

Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not pr…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1992

Published Apr 25, 2006

mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid point…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-1991

Published Apr 24, 2006

The substr_compare function in string.c in PHP 5.1.2 allows context-dependent attackers to cause a denial of service (memory access violation) via an out-of-bounds offset argument.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1525

Published Apr 19, 2006

ip_route_input in Linux kernel 2.6 before 2.6.16.8 allows local users to cause a denial of service (panic) via a request for a route for a multicast IP address, which triggers a n…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-1790

Published Apr 14, 2006

A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, w…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,601-2,625 of 2,694 CVEsPage 105 of 108