5 results (0.014 seconds)

CVSS: 10.0EPSS: 88%CPEs: 345EXPL: 23

25 Sep 2014 — GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a ... • https://packetstorm.news/files/id/128650 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-228: Improper Handling of Syntactically Invalid Structure •

CVSS: 10.0EPSS: 94%CPEs: 345EXPL: 136

24 Sep 2014 — GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." N... • https://packetstorm.news/files/id/181111 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

08 Aug 2007 — The pop3 Proxy in Astaro Security Gateway (ASG) 7 does not perform virus scanning of attachments that exceed the maximum attachment size, and passes these attachments, which allows remote attackers to bypass this scanning via a large attachment. El Proxy pop3 en el Astaro Security Gateway (ASG) 7 no realiza escaneo de virus en los ficheros adjuntos que excedan el tamaño máximo de los adjunto y deja pasar dichos adjuntos, lo que permite a atacantes remotos evitar el escaneo mediante la inclusión de adjuntos ... • http://securityreason.com/securityalert/2981 •

CVSS: 7.8EPSS: 5%CPEs: 7EXPL: 0

08 Aug 2007 — Unspecified vulnerability in pfilter-reporter.pl in Astaro Security Gateway (ASG) 7 allows remote attackers to cause a denial of service (CPU consumption) via certain network traffic, as demonstrated by P2P and iTunes applications that download large amounts of data. Vulnerabilidad no especificada en pfilter-reporter.pl de Astaro Security Gateway (ASG) 7 permite a atacantes remotos provocar una denegación de servicio (consumo de CPU) mediante cierto tráfico de red, como ha sido demostrado por aplicaciones P... • http://astaro.org/showthread.php?p=77667 •

CVSS: 7.8EPSS: 1%CPEs: 1EXPL: 0

18 Jun 2007 — Multiple unspecified vulnerabilities in Astaro Security Gateway (ASG) before 7.005 allow remote attackers to cause a denial of service via (1) certain email, which stops the SMTP Proxy during scanning; (2) certain HTTP traffic, which stops or slows down the HTTP proxy during HTTP responses containing virus scanned web pages; and (3) a disconnection during a streaming session. Múltiples vulnerabilidades no especificadas en Astaro Security Gateway (ASG) anterior a 7.005 permite a atacantes remotos provocar de... • http://osvdb.org/37345 •