Page 264 of 2650 results (0.016 seconds)

CVSS: 9.8EPSS: 25%CPEs: 15EXPL: 2

20 Dec 2002 — Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing negative arguments to be fed into memcpy() calls via HTTP requests with (1) a negative Content-Length value or (2) a negative length in a chunked transfer encoding. • https://www.exploit-db.com/exploits/22106 •

CVSS: 10.0EPSS: 18%CPEs: 15EXPL: 1

20 Dec 2002 — Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as demonstrated by mksun. Múltiples desbordamientos de enteros en Common Unix Printing System (CUPS) 1.1.14 a 1.1.17 permiten a atacantes remotos ejecutar código arbitrario mediante el interfaz HTTP CUPSd, como ha sido demostrado por vanilla-coke, y el código ... • ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-004.0.txt •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

11 Dec 2002 — Mac OS X 10.2.2 allows local users to read files that only allow write access via the map_fd() Mach system call. Mac OS X 10.2.2 permite a usuarios locales la lectura de ficheros que sólo conceden acceso de escritura mediante la llamda al sistema map_fd() Mach. • http://www.info.apple.com/usen/security/security_updates.html •

CVSS: 9.8EPSS: 13%CPEs: 3EXPL: 0

11 Dec 2002 — Multiple buffer overflows in Cyrus SASL library 2.1.9 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long inputs during user name canonicalization, (2) characters that need to be escaped during LDAP authentication using saslauthd, or (3) an off-by-one error in the log writer, which does not allocate space for the null character that terminates a string. Desbordamiento de búfer en la librería Cyrus SASL 2.1.9 y anteriores permite a atacantes remoto... • http://archives.neohapsis.com/archives/linux/suse/2002-q4/1275.html • CWE-131: Incorrect Calculation of Buffer Size •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

11 Dec 2002 — Mac OS X 10.2.2 allows local users to gain privileges by mounting a disk image file that was created on another system, aka "Local User Privilege Elevation via Disk Image File." • http://www.info.apple.com/usen/security/security_updates.html •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

11 Dec 2002 — Mac OS X 10.2.2 allows remote attackers to cause a denial of service by accessing the CUPS Printing Web Administration utility, aka "CUPS Printing Web Administration is Remotely Accessible." • http://www.info.apple.com/usen/security/security_updates.html •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

11 Dec 2002 — Mac OS X 10.2.2 allows local users to gain privileges via a mounted ISO 9600 CD, aka "User Privilege Elevation via Mounting an ISO 9600 CD." Mac OS X 10.2.2 permite a usuarios locales ganar privilegios mediante un CD ISO 9600 montado. Tambíén conocida como "Elevación de privilegios de usuario montando un CD ISO 9600. • http://www.info.apple.com/usen/security/security_updates.html •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

03 Dec 2002 — Unknown vulnerability in NetInfo Manager application in Mac OS X 10.2.2 allows local users to access restricted parts of a filesystem. Vulnerabilidad desconocida en la aplicación NetInfo Manager en Mac OS X 10.2.2 permite a usuarios locales acceder a partes restringidas de un sistema de ficheros. • http://www.info.apple.com/usen/security/security_updates.html •

CVSS: 7.5EPSS: 5%CPEs: 59EXPL: 0

12 Nov 2002 — The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang). La funcionalidad RPC de Sun en múltiples implementaciones de libc no provee de un mecanismo de exceso de tiempo cuando se leen datos de conexiones TCP, lo que permite a atacantes remotos causar una denegación de servicio (cuelgue) • ftp://patches.sgi.com/support/free/security/advisories/20021103-01-P •

CVSS: 7.5EPSS: 5%CPEs: 28EXPL: 0

25 Oct 2002 — IPSEC implementations including (1) FreeS/WAN and (2) KAME do not properly calculate the length of authentication data, which allows remote attackers to cause a denial of service (kernel panic) via spoofed, short Encapsulating Security Payload (ESP) packets, which result in integer signedness errors. Implementaciones de IPSEC, incluyendo FreeS/WAN y KAME no calculan adecuadamente la longitud de los datos de autenticación, lo que permite a atacantes remotos causar una denegación de servicio (kernel panic) me... • ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-016.txt.asc •