Trustix Secure Linux vulnerabilities
65 known vulnerabilities affecting trustix/secure_linux.
Total CVEs
65
CISA KEV
0
Public exploits
21
Exploited in wild
0
Severity breakdown
CRITICAL17HIGH16MEDIUM20LOW12
Vulnerabilities
Page 3 of 4
CVE-2004-0565LOWCVSS 2.1v2v2.0+1 more2004-12-06
CVE-2004-0565 [LOW] CVE-2004-0565: Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit b
Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.
nvd
CVE-2004-0415LOWCVSS 2.1PoCv2.0v2.12004-11-23
CVE-2004-0415 [LOW] CVE-2004-0415: Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local us
Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.
nvd
CVE-2004-0801HIGHCVSS 7.5v2.0v2.12004-09-16
CVE-2004-0801 [HIGH] CVE-2004-0801: Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attacker
Unknown vulnerability in foomatic-rip in Foomatic before 3.0.2 allows local users or remote attackers with access to CUPS to execute arbitrary commands.
nvd
CVE-2004-0809MEDIUMCVSS 5.0v2.0v2.12004-09-16
CVE-2004-0809 [MEDIUM] CVE-2004-0809: The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
nvd
CVE-2004-0432HIGHCVSS 7.5v2.0v2.12004-08-18
CVE-2004-0432 [HIGH] CVE-2004-0432: ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowA
ProFTPD 1.2.9 treats the Allow and Deny directives for CIDR based ACL entries as if they were AllowAll, which could allow FTP clients to bypass intended access restrictions.
nvd
CVE-2004-0421MEDIUMCVSS 5.0v2.0v2.12004-08-18
CVE-2004-0421 [MEDIUM] CWE-125 CVE-2004-0421: The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial
The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.
nvd
CVE-2004-0493MEDIUMCVSS 6.4PoCv1.5v2.0+1 more2004-08-06
CVE-2004-0493 [MEDIUM] CVE-2004-0493: The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a deni
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.
nvd
CVE-2004-0600CRITICALCVSS 10.0PoCv1.5v2.0+1 more2004-07-27
CVE-2004-0600 [CRITICAL] CVE-2004-0600: Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote at
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via an invalid base-64 character during HTTP basic authentication.
nvd
CVE-2004-0594MEDIUMCVSS 5.1PoCv1.5v2.0+1 more2004-07-27
CVE-2004-0594 [MEDIUM] CWE-367 CVE-2004-0594: The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditi
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor pointer before the initialization o
nvd
CVE-2004-0686MEDIUMCVSS 5.0v1.5v2.0+1 more2004-07-27
CVE-2004-0686 [MEDIUM] CVE-2004-0686: Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" optio
Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.
nvd
CVE-2004-0595MEDIUMCVSS 6.8PoCv1.5v2.0+1 more2004-07-27
CVE-2004-0595 [MEDIUM] CVE-2004-0595: The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) ch
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the exploitation of cross-site scripting (XSS) vulner
nvd
CVE-2004-2044HIGHCVSS 7.5PoCv2.0v2.12004-06-01
CVE-2004-2044 [HIGH] CVE-2004-2044: PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuk
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path information via a PHP error message, and possib
nvd
CVE-2004-0077HIGHCVSS 7.2PoCv1.5v2.02004-03-03
CVE-2004-0077 [HIGH] CVE-2004-0077: The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.
nvd
CVE-2002-1319LOWCVSS 2.1v1.1v1.2+1 more2002-12-11
CVE-2002-1319 [LOW] CVE-2002-1319: The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to c
The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.
nvd
CVE-2002-0083CRITICALCVSS 9.8PoCv1.1v1.2+1 more2002-03-15
CVE-2002-0083 [CRITICAL] CWE-193 CVE-2002-0083: Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malic
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
nvd
CVE-2001-1030HIGHCVSS 7.5v1.1v1.01+1 more2001-07-18
CVE-2001-1030 [HIGH] CVE-2001-1030: Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when th
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
nvd
CVE-2001-0169LOWCVSS 2.1PoCv1.1v1.22001-03-26
CVE-2001-0169 [LOW] CVE-2001-0169: When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
nvd
CVE-2001-0142LOWCVSS 1.2v1.1v1.22001-03-12
CVE-2001-0142 [LOW] CVE-2001-0142: squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some c
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
nvd
CVE-2001-0117LOWCVSS 1.2v1.1v1.22001-03-12
CVE-2001-0117 [LOW] CVE-2001-0117: sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
nvd
CVE-2000-0917CRITICALCVSS 10.0PoCv1.0v1.12000-12-19
CVE-2000-0917 [CRITICAL] CVE-2000-0917: Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to exec
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
nvd