Page 18 of 103 results (0.007 seconds)

CVSS: 7.2EPSS: 0%CPEs: 26EXPL: 0

BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id. • http://marc.info/?l=bugtraq&m=98744422105430&w=2 http://www.securityfocus.com/bid/2609 •

CVSS: 5.0EPSS: 0%CPEs: 23EXPL: 0

ip_input.c in BSD-derived TCP/IP implementations allows remote attackers to cause a denial of service (crash or hang) via crafted packets. ip_input.c en implementaciones de TCP/IP derivadas de BSD permiten a atacantes remotos causar una denegación de servicio (cuelgue o caída) mediante paquetes artesanales. • http://www.openbsd.org/errata23.html#tcpfix http://www.osvdb.org/5707 • CWE-20: Improper Input Validation •

CVSS: 7.2EPSS: 0%CPEs: 3EXPL: 0

KDE allows local users to execute arbitrary commands by setting the KDEDIR environmental variable to modify the search path that KDE uses to locate its executables. • http://marc.info/?l=bugtraq&m=91141486301691&w=2 •

CVSS: 2.1EPSS: 0%CPEs: 3EXPL: 0

KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable. • http://marc.info/?l=bugtraq&m=91141486301691&w=2 •

CVSS: 4.6EPSS: 0%CPEs: 3EXPL: 0

KDE klock allows local users to kill arbitrary processes by specifying an arbitrary PID in the .kss.pid file. • http://marc.info/?l=bugtraq&m=91141486301691&w=2 •