CVE-2007-2529
published 2007-05-09CVE-2007-2529: Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and…
PriorityP420high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.37%
28.8th percentile
Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | solaris | — | — |
| sun | sunos | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r7hv-v69f-fvfr: Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) an
ghsa_unreviewed·2022-05-01
CVE-2007-2529 [HIGH] GHSA-r7hv-v69f-fvfr: Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) an
Integer signedness error in the acl (facl) system call in Solaris 10 before 20070507 allows local users to cause a denial of service (kernel panic) and possibly gain privileges via a certain argument, related to ACE_SETACL.
OSV
CVE-2007-5156: Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload
osv·2007-10-01·CVSS 5.0
CVE-2007-5156 CVE-2007-5156: Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.beta, La-Nai CMS, Syntax CMS, Cardinal Cms, and probably other products, allows remote attackers to upload and execute arbitrary PHP code via a file whose name contains ".php." and has an unknown extension, which is recognized as a .php file by the Apache HTTP server, a different vulnerability than CVE-2006-0658 and CVE-2006-2529.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=524http://osvdb.org/34906http://secunia.com/advisories/25162http://securitytracker.com/id?1018009http://sunsolve.sun.com/search/document.do?assetkey=1-26-102869-1http://www.securityfocus.com/bid/23863http://www.vupen.com/english/advisories/2007/1683https://exchange.xforce.ibmcloud.com/vulnerabilities/34147https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1669http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=524http://osvdb.org/34906http://secunia.com/advisories/25162http://securitytracker.com/id?1018009http://sunsolve.sun.com/search/document.do?assetkey=1-26-102869-1http://www.securityfocus.com/bid/23863http://www.vupen.com/english/advisories/2007/1683https://exchange.xforce.ibmcloud.com/vulnerabilities/34147https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1669
2007-05-09
Published