CVE-2004-0996 – Cscope 13.0/15.x - Insecure Temporary File Creation
https://notcve.org/view.php?id=CVE-2004-0996
main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack. main.c de cscope 15-4 y 15-5 crea ficheros temporales con nombres predecibles, lo que permite a usuarios locales sobreescribir ficheros de su elección mediante un ataque de enlaces simbólicos. • https://www.exploit-db.com/exploits/24750 https://www.exploit-db.com/exploits/24749 http://docs.info.apple.com/article.html?artnum=306172 http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.html http://marc.info/?l=bugtraq&m=110133485519690&w=2 http://secunia.com/advisories/26235 http://www.debian.org/security/2004/dsa-610 http://www.gentoo.org/security/en/glsa/glsa-200412-11.xml http://www.securityfocus.com/archive/1/381443 http://www.securit •
CVE-2004-0981
https://notcve.org/view.php?id=CVE-2004-0981
Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file. • http://secunia.com/advisories/12995 http://security.gentoo.org/glsa/glsa-200411-11.xml http://www.imagemagick.org/www/Changelog.html http://www.securityfocus.org/bid/11548 https://exchange.xforce.ibmcloud.com/vulnerabilities/17903 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10472 https://www.ubuntu.com/usn/usn-7-1 https://access.redhat.com/security/cve/CVE-2004-0981 https://bugzilla.redhat.com/show_bug.cgi?id=1617341 •
CVE-2004-0980
https://notcve.org/view.php?id=CVE-2004-0980
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code. • http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028590.html http://secunia.com/advisories/13167 http://www.debian.org/security/2004/dsa-592 http://www.gentoo.org/security/en/glsa/glsa-200411-20.xml http://www.mandriva.com/security/advisories?name=MDKSA-2004:129 http://www.securityfocus.com/bid/11657 https://exchange.xforce.ibmcloud.com/vulnerabilities/18032 •
CVE-2004-1051
https://notcve.org/view.php?id=CVE-2004-1051
sudo before 1.6.8p2 allows local users to execute arbitrary commands by using "()" style environment variables to create functions that have the same name as any program within the bash script that is called without using the program's full pathname. • http://lists.apple.com/archives/security-announce/2005/May/msg00001.html http://marc.info/?l=bugtraq&m=110028877431192&w=2 http://marc.info/?l=bugtraq&m=110598298225675&w=2 http://www.debian.org/security/2004/dsa-596 http://www.mandriva.com/security/advisories?name=MDKSA-2004:133 http://www.securityfocus.com/bid/11668 http://www.sudo.ws/sudo/alerts/bash_functions.html http://www.trustix.org/errata/2004/0061 https://exchange.xforce.ibmcloud.com/vulnerabilities/18055 https& •
CVE-2004-1052
https://notcve.org/view.php?id=CVE-2004-1052
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters. • http://marc.info/?l=bugtraq&m=110011817627839&w=2 http://secunia.com/advisories/13149 http://security.lss.hr/en/index.php?page=details&ID=LSS-2004-11-03 http://www.debian.org/security/2004/dsa-595 http://www.securityfocus.com/bid/11647 https://exchange.xforce.ibmcloud.com/vulnerabilities/18013 •