Page 20 of 252 results (0.010 seconds)

CVSS: 10.0EPSS: 17%CPEs: 111EXPL: 2

The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337. • https://www.exploit-db.com/exploits/24 https://www.exploit-db.com/exploits/22442 ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-016.0.txt ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-03:07.sendmail.asc ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2004.11/SCOSA-2004.11.txt ftp://patches.sgi.com/support/free/security/advisories/20030401-01-P http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000614 http://lists.apple.com/mhonarc/secur •

CVSS: 7.5EPSS: 96%CPEs: 165EXPL: 1

Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391. Desbordamiento de entero en la función xdrmem_getbytes(), y posiblemente otras funciones, de librerias XDR (representación de datos externos) derivadas de SunRPC, incluyendo libnsl, libc y glibc permite a atacantes remotos ejecutar código arbitrario mediante ciertos valores enteros en campos de longitud. • ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2003-008.txt.asc http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0140.html http://marc.info/?l=bugtraq&m=104810574423662&w=2 http://marc.info/?l=bugtraq&m=104811415301340&w=2 http://marc.info/?l=bugtraq&m=104860855114117&w=2 http://marc.info/?l=bugtraq&m=104878237121402&w=2 http://marc.info/? •

CVSS: 4.6EPSS: 0%CPEs: 3EXPL: 2

Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of service and possibly execute arbitrary code. Múltiples desbordamientos de búfer en el subsistema lp de HP-UX 10.20 a 11.11 (11i) permite a usuarios locales causar una denegación de servicio y posiblemente ejecutar código arbitrario. • https://www.exploit-db.com/exploits/16927 https://www.exploit-db.com/exploits/10034 http://archives.neohapsis.com/archives/hp/2002-q3/0064.html http://www.iss.net/security_center/static/9992.php •

CVSS: 2.1EPSS: 0%CPEs: 3EXPL: 1

ptrace on HP-UX 11.00 through 11.11 allows local users to cause a denial of service (data page fault panic) via "an incorrect reference to thread register state." ptrace sobre HP-UX 11.0 hasta 11.11 permite que usuarios locales causen una denegación de servicio mediante "una referencia incorrecta al estado del registro de threads" • http://archives.neohapsis.com/archives/hp/2002-q3/0041.html http://www.iss.net/security_center/static/9818.php http://www.securityfocus.com/bid/5425 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5584 •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

Unknown vulnerability in passwd for VVOS HP-UX 11.04, with unknown impact, related to "Unexpected behavior." Vulnerabilidad desconocida en passwd para VVOS HP-UX 11.04, con impacto también desconocido, relacionada con "Unexpected behavior". • http://archives.neohapsis.com/archives/hp/2002-q3/0049.html http://www.iss.net/security_center/static/9847.php http://www.securityfocus.com/bid/5454 •