| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-3649 | 0.00 | — | 0.03 | Nov 17, 2005 | jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter. | |||
| CVE-2005-3650 | 0.01 | — | 0.06 | Nov 17, 2005 | The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode. | |||
| CVE-2005-3633 | 0.00 | — | 0.02 | Nov 16, 2005 | HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitrary HTML headers via the sap-exiturl parameter. | |||
| CVE-2005-3634 | 0.04 | — | 0.16 | Nov 16, 2005 | frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter. | |||
| CVE-2005-3635 | 0.03 | — | 0.05 | Nov 16, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application. | |||
| CVE-2005-3636 | 0.03 | — | 0.05 | Nov 16, 2005 | Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages. | |||
| CVE-2005-3638 | 0.03 | — | 0.02 | Nov 16, 2005 | Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in profile.php and (2) titles of posts. | |||
| CVE-2005-3639 | 0.03 | — | 0.03 | Nov 16, 2005 | PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability. | |||
| CVE-2005-3640 | 0.04 | — | 0.09 | Nov 16, 2005 | Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to execute arbitrary code via long arguments to various IMAP commands, as demonstrated with the EXAMINE command. | |||
| CVE-2005-3641 | 0.00 | — | 0.05 | Nov 16, 2005 | Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username. | |||
| CVE-2005-3642 | 0.00 | — | 0.01 | Nov 16, 2005 | IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username. | |||
| CVE-2005-3643 | 0.00 | — | 0.01 | Nov 16, 2005 | IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password. | |||
| CVE-2005-3621 | 0.00 | — | 0.02 | Nov 16, 2005 | CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts. | |||
| CVE-2005-3622 | 0.00 | — | 0.02 | Nov 16, 2005 | phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory. | |||
| CVE-2005-2659 | 0.00 | — | 0.02 | Nov 16, 2005 | Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors. | |||
| CVE-2005-3344 | 0.01 | — | 0.08 | Nov 16, 2005 | The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access. | |||
| CVE-2005-3543 | 0.00 | — | 0.01 | Nov 16, 2005 | SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter. | |||
| CVE-2005-3544 | 0.03 | — | 0.05 | Nov 16, 2005 | Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |||
| CVE-2005-3545 | 0.03 | — | 0.02 | Nov 16, 2005 | SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter. | |||
| CVE-2005-3546 | 0.03 | — | 0.01 | Nov 16, 2005 | suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege. | |||
| CVE-2005-3547 | 0.03 | — | 0.03 | Nov 16, 2005 | Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) adsess, (2) name, and (3) description parameters in admin.php, and the (4) ACP Notes, (5) Member Name, (6) Password, (7) Email Address,… | |||
| CVE-2005-3548 | 0.00 | — | 0.01 | Nov 16, 2005 | Directory traversal vulnerability in Task Manager in Invision Power Board (IP.Board) 2.0.1 allows limited remote attackers to include files via a .. (dot dot) in the "Task PHP File To Run" field. | |||
| CVE-2005-3549 | 0.00 | — | 0.02 | Nov 16, 2005 | Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now". | |||
| CVE-2005-3550 | 0.04 | — | 0.06 | Nov 16, 2005 | Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter. | |||
| CVE-2005-3551 | 0.00 | — | 0.01 | Nov 16, 2005 | toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file. | |||
| CVE-2005-3552 | 0.00 | — | 0.02 | Nov 16, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer… | |||
| CVE-2005-3553 | 0.00 | — | 0.02 | Nov 16, 2005 | Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in conjunction with the login/userinfo.php path and (2) the session parameter (aka the PHPKITSID variable). | |||
| CVE-2005-3554 | 0.00 | — | 0.03 | Nov 16, 2005 | Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary code on the server via unknown attack vectors involving uninitialized variables. | |||
| CVE-2005-3555 | 0.03 | — | 0.02 | Nov 16, 2005 | Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arbitrary SQL commands via the id parameter in the (1) editattributes or (2) admin page. | |||
| CVE-2005-3556 | 0.03 | — | 0.04 | Nov 16, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) title field in (c)… | |||
| CVE-2005-3557 | 0.00 | — | 0.02 | Nov 16, 2005 | Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request. | |||
| CVE-2005-3558 | 0.03 | — | 0.06 | Nov 16, 2005 | PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1) page and (2) site parameters. | |||
| CVE-2005-3559 | 0.05 | — | 0.20 | Nov 16, 2005 | Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter. | |||
| CVE-2005-3560 | 0.04 | — | 0.14 | Nov 16, 2005 | Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in… | |||
| CVE-2005-3564 | 0.00 | — | 0.00 | Nov 16, 2005 | envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors. | |||
| CVE-2005-3565 | 0.00 | — | 0.03 | Nov 16, 2005 | Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors. | |||
| CVE-2005-3566 | 0.03 | — | 0.01 | Nov 16, 2005 | Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8)… | |||
| CVE-2005-3567 | 0.00 | — | 0.01 | Nov 16, 2005 | slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors. | |||
| CVE-2005-3568 | 0.00 | — | 0.00 | Nov 16, 2005 | db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING." | |||
| CVE-2005-3569 | 0.00 | — | 0.01 | Nov 16, 2005 | INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files. | |||
| CVE-2005-3570 | 0.00 | — | 0.02 | Nov 16, 2005 | Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages". | |||
| CVE-2005-3571 | 0.03 | — | 0.03 | Nov 16, 2005 | PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is… | |||
| CVE-2005-3572 | 0.00 | — | 0.01 | Nov 16, 2005 | SQL injection vulnerability in index.php in Peel 2.6 through 2.7 allows remote attackers to execute arbitrary SQL commands via the rubid parameter. | |||
| CVE-2005-3573 | 0.00 | — | 0.03 | Nov 16, 2005 | Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to cause a denial of service (application crash). | |||
| CVE-2005-3574 | 0.00 | — | 0.01 | Nov 16, 2005 | PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter. | |||
| CVE-2005-3575 | 0.03 | — | 0.01 | Nov 16, 2005 | SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2005-3576 | 0.03 | — | 0.03 | Nov 16, 2005 | ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter. | |||
| CVE-2005-3577 | 0.03 | — | 0.02 | Nov 16, 2005 | Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter. | |||
| CVE-2005-3578 | 0.03 | — | 0.01 | Nov 16, 2005 | SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter. | |||
| CVE-2005-3579 | 0.03 | — | 0.03 | Nov 16, 2005 | ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring. |
- CVE-2005-3649Nov 17, 2005risk 0.00cvss —epss 0.03
jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.
- CVE-2005-3650Nov 17, 2005risk 0.01cvss —epss 0.06
The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.
- CVE-2005-3633Nov 16, 2005risk 0.00cvss —epss 0.02
HTTP response splitting vulnerability in frameset.htm in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to inject arbitrary HTML headers via the sap-exiturl parameter.
- CVE-2005-3634Nov 16, 2005risk 0.04cvss —epss 0.16
frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.
- CVE-2005-3635Nov 16, 2005risk 0.03cvss —epss 0.05
Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.
- CVE-2005-3636Nov 16, 2005risk 0.03cvss —epss 0.05
Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages.
- CVE-2005-3638Nov 16, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in profile.php and (2) titles of posts.
- CVE-2005-3639Nov 16, 2005risk 0.03cvss —epss 0.03
PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.
- CVE-2005-3640Nov 16, 2005risk 0.04cvss —epss 0.09
Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to execute arbitrary code via long arguments to various IMAP commands, as demonstrated with the EXAMINE command.
- CVE-2005-3641Nov 16, 2005risk 0.00cvss —epss 0.05
Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.
- CVE-2005-3642Nov 16, 2005risk 0.00cvss —epss 0.01
IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.
- CVE-2005-3643Nov 16, 2005risk 0.00cvss —epss 0.01
IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.
- CVE-2005-3621Nov 16, 2005risk 0.00cvss —epss 0.02
CRLF injection vulnerability in phpMyAdmin before 2.6.4-pl4 allows remote attackers to conduct HTTP response splitting attacks via unspecified scripts.
- CVE-2005-3622Nov 16, 2005risk 0.00cvss —epss 0.02
phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory.
- CVE-2005-2659Nov 16, 2005risk 0.00cvss —epss 0.02
Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.
- CVE-2005-3344Nov 16, 2005risk 0.01cvss —epss 0.08
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.
- CVE-2005-3543Nov 16, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.
- CVE-2005-3544Nov 16, 2005risk 0.03cvss —epss 0.05
Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
- CVE-2005-3545Nov 16, 2005risk 0.03cvss —epss 0.02
SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.
- CVE-2005-3546Nov 16, 2005risk 0.03cvss —epss 0.01
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.
- CVE-2005-3547Nov 16, 2005risk 0.03cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web script or HTML via the (1) adsess, (2) name, and (3) description parameters in admin.php, and the (4) ACP Notes, (5) Member Name, (6) Password, (7) Email Address,…
- CVE-2005-3548Nov 16, 2005risk 0.00cvss —epss 0.01
Directory traversal vulnerability in Task Manager in Invision Power Board (IP.Board) 2.0.1 allows limited remote attackers to include files via a .. (dot dot) in the "Task PHP File To Run" field.
- CVE-2005-3549Nov 16, 2005risk 0.00cvss —epss 0.02
Direct code injection vulnerability in Task Manager in Invision Power Board 2.0.1 allows limited remote attackers to execute arbitrary code by referencing the file in "Task PHP File To Run" field and selecting "Run Task Now".
- CVE-2005-3550Nov 16, 2005risk 0.04cvss —epss 0.06
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.
- CVE-2005-3551Nov 16, 2005risk 0.00cvss —epss 0.01
toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file.
- CVE-2005-3552Nov 16, 2005risk 0.00cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, and the (5) referer…
- CVE-2005-3553Nov 16, 2005risk 0.00cvss —epss 0.02
Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in conjunction with the login/userinfo.php path and (2) the session parameter (aka the PHPKITSID variable).
- CVE-2005-3554Nov 16, 2005risk 0.00cvss —epss 0.03
Multiple eval injection vulnerabilities in the help function in PHPKIT 1.6.1 R2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary code on the server via unknown attack vectors involving uninitialized variables.
- CVE-2005-3555Nov 16, 2005risk 0.03cvss —epss 0.02
Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arbitrary SQL commands via the id parameter in the (1) editattributes or (2) admin page.
- CVE-2005-3556Nov 16, 2005risk 0.03cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) title field in (c)…
- CVE-2005-3557Nov 16, 2005risk 0.00cvss —epss 0.02
Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request.
- CVE-2005-3558Nov 16, 2005risk 0.03cvss —epss 0.06
PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1) page and (2) site parameters.
- CVE-2005-3559Nov 16, 2005risk 0.05cvss —epss 0.20
Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.
- CVE-2005-3560Nov 16, 2005risk 0.04cvss —epss 0.14
Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in…
- CVE-2005-3564Nov 16, 2005risk 0.00cvss —epss 0.00
envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.
- CVE-2005-3565Nov 16, 2005risk 0.00cvss —epss 0.03
Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.
- CVE-2005-3566Nov 16, 2005risk 0.03cvss —epss 0.01
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8)…
- CVE-2005-3567Nov 16, 2005risk 0.00cvss —epss 0.01
slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.
- CVE-2005-3568Nov 16, 2005risk 0.00cvss —epss 0.00
db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."
- CVE-2005-3569Nov 16, 2005risk 0.00cvss —epss 0.01
INSO service in IBM DB2 Content Manager before 8.2 Fix Pack 10 on AIX allows attackers to cause a denial of service (application crash) via unknown attack vectors involving LZH files.
- CVE-2005-3570Nov 16, 2005risk 0.00cvss —epss 0.02
Unspecified cross-site scripting (XSS) vulnerability in Horde before 2.2.9 allows remote attackers to inject arbitrary web script or HTML via "not properly escaped error messages".
- CVE-2005-3571Nov 16, 2005risk 0.03cvss —epss 0.03
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is…
- CVE-2005-3572Nov 16, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in index.php in Peel 2.6 through 2.7 allows remote attackers to execute arbitrary SQL commands via the rubid parameter.
- CVE-2005-3573Nov 16, 2005risk 0.00cvss —epss 0.03
Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to cause a denial of service (application crash).
- CVE-2005-3574Nov 16, 2005risk 0.00cvss —epss 0.01
PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter.
- CVE-2005-3575Nov 16, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2005-3576Nov 16, 2005risk 0.03cvss —epss 0.03
ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.
- CVE-2005-3577Nov 16, 2005risk 0.03cvss —epss 0.02
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.
- CVE-2005-3578Nov 16, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.
- CVE-2005-3579Nov 16, 2005risk 0.03cvss —epss 0.03
ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.