Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Damyan Ivanov

Pesquisador deDebian community
#21478de 53,639
11.3CVSS total
Vulnerabilidades · 2
Média
2
PT-2014-6374
6.3
2014-08-16
Xml-Dt · Xml-Dt · CVE-2014-5260
**Name of the Vulnerable Software and Affected Versions** XML-DT versions prior to 0.64 **Description** The issue allows local users to overwrite arbitrary files via a symlink attack on a /tmp/ xml ##### temporary file. This is possible due to vulnerabilities in the `mkxmltype` and `mkdtskel` scripts. **Recommendations** For versions prior to 0.64, update to version 0.64 or later to resolve the issue. As a temporary workaround, consider restricting access to the `mkxmltype` and `mkdtskel` scripts until the update is applied.
PT-2004-2939
5.0
2004-05-01
Firebird · Firebird Database · CVE-2004-2043
**Name of the Vulnerable Software and Affected Versions** Firebird Database versions 1.0 through 1.5 **Description** A buffer overflow issue in the ibserver component allows remote attackers to cause a denial of service by crashing the system with a long database name. This can be demonstrated using the gsec command. **Recommendations** For Firebird Database versions 1.0 through 1.5, update to version 1.5 or later to resolve the issue.