CVE-2007-2138 (Medium) :
Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x
before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4 allows remote authenticated users,
when permitted to call a SECURITY DEFINER function, to gain the privileges of the function owner,
related to "search_path settings."
CVE-2007-4769 (Medium) :
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1
before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to
cause a denial of service (backend crash) via an out-of-bounds backref number.
CVE-2007-4772 (Medium) :
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1
before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to
cause a denial of service (infinite loop) via a crafted regular expression.
CVE-2007-6067 (Medium) :
Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as
used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19,
allows remote authenticated users to cause a denial of service (memory consumption) via a
crafted "complex" regular expression with doubly-nested states.
CVE-2007-6600 (Medium) :
PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3
before 7.3.21 uses superuser privileges instead of table owner privileges for (1) VACUUM and (2)
ANALYZE operations within index functions, and supports (3) SET ROLE and (4) SET SESSION
AUTHORIZATION within index functions, which allows remote authenticated users to gain
privileges.
CVE-2007-6601 (High) :
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4
before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows
remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of
an incomplete fix for CVE-2007-3278.
Note: This assures that the 'curl-config' script will be generated properly,
also including the right prefix to the heimdal libs.
Nevertheless heimdal support has to be reimplemented from scratch!
CVE-2006-5752 (Medium) :
Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP
Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows
remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets
with browsers that perform "charset detection" when the content-type is not specified.
CVE-2007-1862 (Medium) :
The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels
of header data, which can cause Apache to return HTTP headers containing previously used data,
which could be used by remote attackers to obtain potentially sensitive information.
CVE-2007-1863 (Medium) :
cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled
and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a
denial of service (child processing handler crash) via a request with the (1) s-maxage, (2)
max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value.
CVE-2007-3304 (Medium) :
Apache httpd 1.3.37, 2.0.59, and 2.2.4 with the Prefork MPM module, allows local users to cause a
denial of service by modifying the worker_score and process_score arrays to reference an
arbitrary process ID, which is sent a SIGUSR1 signal from the master process, aka "SIGUSR1
killer."
CVE-2007-3847 (Medium) :
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a
threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy
process crash) via crafted date headers that trigger a buffer over-read.
CVE-2007-5000 (Medium) :
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server
1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache
HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via
unspecified vectors.
CVE-2007-6388 (Medium) :
Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through
2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled,
allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2007-6421 (Low) :
Cross-site scripting (XSS) vulnerability in balancer-manager in mod_proxy_balancer in the Apache
HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via
the (1) ss, (2) wr, or (3) rr parameters, or (4) the URL.
CVE-2007-6422 (Medium) :
The balancer_handler function in mod_proxy_balancer in the Apache HTTP Server 2.2.0 through
2.2.6, when a threaded Multi-Processing Module is used, allows remote authenticated users to
cause a denial of service (child process crash) via an invalid bb variable.
CVE-2008-0005 (Medium) :
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before
1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site
scripting (XSS) attacks using UTF-7 encoding.
CVE-2007-1543 (High) :
Stack-based buffer overflow in the accept_att_local function in server/os/connection.c in Network
Audio System (NAS) before 1.8a SVN 237 allows remote attackers to execute arbitrary code via a
long path slave name in a USL socket connection.
CVE-2007-1544 (Medium) :
Integer overflow in the ProcAuWriteElement function in server/dia/audispatch.c in Network Audio
System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash)
and possibly execute arbitrary code via a large max_samples value.
CVE-2007-1545 (Medium) :
The AddResource function in server/dia/resource.c in Network Audio System (NAS) before 1.8a
SVN 237 allows remote attackers to cause a denial of service (server crash) via a nonexistent
client ID.
CVE-2007-1546 (Medium) :
Array index error in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to
cause a denial of service (crash) via (1) large num_action values in the ProcAuSetElements
function in server/dia/audispatch.c or (2) a large inputNum parameter to the compileInputs function
in server/dia/auutil.c.
CVE-2007-1547 (High) :
The ReadRequestFromClient function in server/os/io.c in Network Audio System (NAS) before
1.8a SVN 237 allows remote attackers to cause a denial of service (crash) via multiple
simultaneous connections, which triggers a NULL pointer dereference.