licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| conectiva | linux | 4.1 |
| conectiva | linux | 5.0 |
| freebsd | freebsd | 3.5.1 |
| mandrakesoft | mandrake_linux | 7.1 |
| mandrakesoft | mandrake_linux | 7.2 |
| conectiva | linux | 4.0 |
| redhat | linux | 7.0 |
| conectiva | linux | 4.0es |
| licq | licq | * |
| conectiva | linux | 4.2 |
| freebsd | freebsd | 4.2 |
| mandrakesoft | mandrake_linux_corporate_server | 1.0.1 |
Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| conectiva | linux | 4.1 |
| conectiva | linux | 5.0 |
| mandrakesoft | mandrake_linux | 7.1 |
| conectiva | linux | ecommerce |
| conectiva | linux | prg_graficos |
| conectiva | linux | 6.0 |
| mandrakesoft | mandrake_linux | 7.2 |
| conectiva | linux | 4.0 |
| conectiva | linux | 4.0es |
| licq | licq | * |
| conectiva | linux | 4.2 |
| conectiva | linux | 5.1 |
Buffer overflow in licq 1.0.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string of format string characters such as "%d".
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| licq | licq | 1.0 |
| licq | licq | 1.0.1 |
| licq | licq | 1.0.3 |
| licq | licq | 1.0.4 |
| licq | licq | 1.0.2 |
Format string vulnerability in LICQ 1.2.6, 1.0.3 and possibly other versions allows remote attackers to perform unknown actions via format string specifiers.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| licq | licq | 1.0.3 |
| licq | licq | 1.2.6 |
licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash) via a large number of connections.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| licq | licq | 0.61 |
| licq | licq | 1.3.2 |
| licq | licq | 1.3.2_rc |
| licq | licq | 0.75.1 |
| licq | licq | 1.2.6 |
| licq | licq | 0.76 |
| licq | licq | 1.2.3 |
| licq | licq | 0.84b |
| licq | licq | 0.75_991219 |
| licq | licq | 1.2 |
| licq | licq | 0.84a |
| licq | licq | 0.80 |
| licq | licq | 1.0.3 |
| licq | licq | 1.0.4 |
| licq | licq | 1.2.4 |
| licq | licq | 0.75 |
| licq | licq | 0.75.3 |
| licq | licq | 0.75.3a |
| licq | licq | 0.85 |
| licq | licq | 1.0.2 |
| licq | licq | 0.71 |
| licq | licq | 1.0 |
| licq | licq | 1.3.0 |
| licq | licq | 1.0.1 |
| licq | licq | 1.3.0_pre |
| licq | licq | 1.2.7 |
| licq | licq | 1.3.5 |
| licq | licq | 1.3.4 |
| licq | licq | 0.75.2 |
| licq | licq | 0.81 |