VYPR

CVEs

342,869 total · page 6579 of 6,858

  • CVE-2005-3524Nov 7, 2005
    risk 0.05cvss epss 0.21

    Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.

  • CVE-2005-3519Nov 6, 2005
    risk 0.04cvss epss 0.08

    Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in…

  • CVE-2005-3520Nov 6, 2005
    risk 0.03cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the target_url parameter in upgrade_in_progress_backend.php, (2) the stylesheet parameter in edit_table_cell_type_wysiwyg.php, and the…

  • CVE-2005-3521Nov 6, 2005
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.

  • CVE-2005-3522Nov 6, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.

  • CVE-2005-3124Nov 6, 2005
    risk 0.00cvss epss 0.00

    syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.

  • CVE-2005-3507Nov 6, 2005
    risk 0.04cvss epss 0.12

    Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.

  • CVE-2005-3508Nov 6, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in showGallery.php in Gallery (Galerie) 2.4 allows remote attackers to execute arbitrary SQL commands via the galid parameter.

  • CVE-2005-3509Nov 6, 2005
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.

  • CVE-2005-3510Nov 6, 2005
    risk 0.00cvss epss 0.06

    Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

  • CVE-2005-3511Nov 6, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS 4.0 allow remote attackers to inject arbitrary web script or HTML via (a) the blogs module, including the (1) curr parameter in index.php, (2) inspire, (3) system, or (4) title parameter in blog_newentry.php,…

  • CVE-2005-3512Nov 6, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via the t parameter in a newreply action.

  • CVE-2005-3513Nov 6, 2005
    risk 0.00cvss epss 0.01

    index.php in VUBB alpha rc1 allows remote attackers to obtain the installation path of the application via a viewforum action with the f parameter set to a single quote (').

  • CVE-2005-3514Nov 6, 2005
    risk 0.03cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the forumID parameter to (1) newtopic.php, (2) quote.php, (3) index.php, and (4) reply.php.

  • CVE-2005-3515Nov 6, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

  • CVE-2005-3516Nov 6, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter.

  • CVE-2005-3517Nov 6, 2005
    risk 0.00cvss epss 0.01

    Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.

  • CVE-2005-3518Nov 6, 2005
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter.

  • CVE-2005-2628Nov 5, 2005
    risk 0.01cvss epss 0.07

    Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.

  • CVE-2005-2753Nov 5, 2005
    risk 0.00cvss epss 0.02

    Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.

  • CVE-2005-2754Nov 5, 2005
    risk 0.00cvss epss 0.02

    Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."

  • CVE-2005-2755Nov 5, 2005
    risk 0.00cvss epss 0.02

    Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.

  • CVE-2005-2756Nov 5, 2005
    risk 0.00cvss epss 0.04

    Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.

  • CVE-2005-3303Nov 5, 2005
    risk 0.01cvss epss 0.07

    The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.

  • CVE-2005-3500Nov 5, 2005
    risk 0.00cvss epss 0.04

    The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block.

  • CVE-2005-3501Nov 5, 2005
    risk 0.00cvss epss 0.04

    The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length.

  • CVE-2005-3502Nov 5, 2005
    risk 0.00cvss epss 0.02

    attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.

  • CVE-2005-3503Nov 5, 2005
    risk 0.03cvss epss 0.03

    chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.

  • CVE-2005-3504Nov 5, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.

  • CVE-2005-3505Nov 5, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the Entropy Chat script in cPanel 10.2.0-R82 and 10.6.0-R137 allows remote attackers to inject arbitrary web script or HTML via a chat message containing Javascript in style attributes in tags such as , which are processed by…

  • CVE-2005-3506Nov 5, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in proxy.asp in Sambar Server 6.3 BETA 2 and possibly earlier versions allows remote attackers to inject arbitrary web script or HTML via the (1) Remote Proxy Server or (2) Proxy Filter IPs field.

  • CVE-2005-2974Nov 4, 2005
    risk 0.00cvss epss 0.03

    libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.

  • CVE-2005-3350Nov 4, 2005
    risk 0.00cvss epss 0.04

    libungif library before 4.1.0 allows attackers to corrupt memory and possibly execute arbitrary code via a crafted GIF file that leads to an out-of-bounds write.

  • CVE-2005-3489Nov 4, 2005
    risk 0.03cvss epss 0.06

    Buffer overflow in Asus Video Security 3.5.0.0 and earlier, when using authorization, allows remote attackers to execute arbitrary code via a long username/password string.

  • CVE-2005-3490Nov 4, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the web server in Asus Video Security 3.5.0.0 and earlier allows remote attackers to read arbitrary files via "../" or "..\" sequences in the URL.

  • CVE-2005-3491Nov 4, 2005
    risk 0.03cvss epss 0.05

    Multiple buffer overflows in the receiver function in loop.c in FlatFrag 0.3 and earlier allow remote attackers to execute arbitrary code via the (1) version, (2) name, and (3) model fields.

  • CVE-2005-3492Nov 4, 2005
    risk 0.03cvss epss 0.04

    FlatFrag 0.3 and earlier allows remote attackers to cause a denial of service (crash) by sending an NT_CONN_OK command from a client that is not connected, which triggers a null dereference.

  • CVE-2005-3493Nov 4, 2005
    risk 0.03cvss epss 0.03

    Battle Carry .005 and earlier allows remote attackers to cause a denial of service (inaccessible port) via a large packet, which triggers a socket error and terminates the socket that is listening on the server's UDP port.

  • CVE-2005-3494Nov 4, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Ar-blog 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog comment.

  • CVE-2005-3495Nov 4, 2005
    risk 0.00cvss epss 0.02

    Ar-blog 5.2 and earlier allows remote attackers to bypass authentication by modifying cookies.

  • CVE-2005-3496Nov 4, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in PHP Handicapper allows remote attackers to inject arbitrary web script or HTML via the msg parameter to msg.php. NOTE: some sources identify a second vector in the login parameter to process_signup.php, but the original source says…

  • CVE-2005-3497Nov 4, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in process_signup.php in PHP Handicapper allows remote attackers to execute arbitrary SQL commands via the serviceid parameter. NOTE: on 20060210, the vendor disputed this issue, saying "this is 100% false reporting, this is a slander campaign from a…

  • CVE-2005-3498Nov 4, 2005
    risk 0.04cvss epss 0.11

    IBM WebSphere Application Server 5.0.x before 5.02.15, 5.1.x before 5.1.1.8, and 6.x before fixpack V6.0.2.5, when session trace is enabled, records a full URL including the queryString in the trace logs when an application encodes a URL, which could allow attackers to obtain…

  • CVE-2005-3499Nov 4, 2005
    risk 0.00cvss epss 0.03

    Frisk F-Prot Antivirus allows remote attackers to bypass protection via a ZIP file with a version header greater than 15, which prevents F-Prot from decompressing and analyzing the file.

  • CVE-2005-3483Nov 3, 2005
    risk 0.04cvss epss 0.07

    Buffer overflow in GO-Global for Windows 3.1.0.3270 and earlier allows remote attackers to execute arbitrary code via a data block that is longer than the specified data block size.

  • CVE-2005-3484Nov 3, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in NeroNET 1.2.0.2 and earlier allows remote attackers to read arbitrary files with certain file extensions (such as ZIP, AVI, JPG, TXT, and HTML) via ".." and hex-encoded (1) slash "/" ("%2f") or (2) backslash "\" ("%5c") sequences.

  • CVE-2005-3485Nov 3, 2005
    risk 0.03cvss epss 0.06

    Buffer overflow in Glider Collect'n kill 1.0.0.0 allows remote attackers to execute arbitrary code via a gl_playerEnter command with a long player name.

  • CVE-2005-3486Nov 3, 2005
    risk 0.04cvss epss 0.11

    Multiple format string vulnerabilities in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, and possibly other unspecified vectors.

  • CVE-2005-3487Nov 3, 2005
    risk 0.04cvss epss 0.08

    Multiple buffer overflows in Scorched 3D 39.1 (bf) and earlier allow remote attackers to execute arbitrary code via various (1) GLConsole::addLine, (2) ServerCommon::sendString, (3) ServerCommon::serverLog functions, (4) a long command that is not properly handled in…

  • CVE-2005-3488Nov 3, 2005
    risk 0.04cvss epss 0.10

    Scorched 3D 39.1 (bf) and earlier allows remote attackers to cause a denial of service (long loop and server hang) via a negative numplayers value that bypasses a signed check in ServerConnectHandler.cpp.