VYPR

CVEs

342,869 total · page 6586 of 6,858

  • CVE-2005-3235Oct 14, 2005
    risk 0.00cvss epss 0.02

    Multiple interpretation error in unspecified versions of Proland Protector Plus 2000 Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by…

  • CVE-2005-3236Oct 14, 2005
    risk 0.03cvss epss 0.04

    Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain administrative access via (1) the fid parameter of newmsg.php, which can enable XSS attacks when the SQL syntax is invalid or (2) the nick parameter of lostpwd.php.

  • CVE-2005-3237Oct 14, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote attackers to inject arbitrary web script or HTML via the t_login parameter of footer.php.

  • CVE-2005-2933Oct 13, 2005
    risk 0.01cvss epss 0.08

    Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes…

  • CVE-2005-2943Oct 13, 2005
    risk 0.04cvss epss 0.15

    Stack-based buffer overflow in sendmail in XMail before 1.22 allows remote attackers to execute arbitrary code via a long -t command line option.

  • CVE-2005-2992Oct 13, 2005
    risk 0.00cvss epss 0.00

    arc 5.21j and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different type of vulnerability than CVE-2005-2945.

  • CVE-2005-3185Oct 13, 2005
    risk 0.00cvss epss 0.05

    Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username.

  • CVE-2005-3190Oct 13, 2005
    risk 0.08cvss epss 0.66

    Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows remote attackers to execute arbitrary code via HTTP GET requests.

  • CVE-2005-2963Oct 13, 2005
    risk 0.00cvss epss 0.02

    The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to…

  • CVE-2005-1985Oct 13, 2005
    risk 0.03cvss epss 0.36

    The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.

  • CVE-2005-1987Oct 13, 2005
    risk 0.03cvss epss 0.43

    Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type"…

  • CVE-2005-2120Oct 13, 2005
    risk 0.08cvss epss 0.63

    Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name,…

  • CVE-2005-2715Oct 12, 2005
    risk 0.08cvss epss 0.60

    Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the…

  • CVE-2005-3183Oct 12, 2005
    risk 0.00cvss epss 0.02

    The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds read.

  • CVE-2005-1978Oct 12, 2005
    risk 0.07cvss epss 0.57

    COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.

  • CVE-2005-1979Oct 12, 2005
    risk 0.06cvss epss 0.36

    Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol…

  • CVE-2005-1980Oct 12, 2005
    risk 0.05cvss epss 0.36

    Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs,…

  • CVE-2005-2119Oct 12, 2005
    risk 0.06cvss epss 0.39

    The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is…

  • CVE-2005-2128Oct 12, 2005
    risk 0.03cvss epss 0.40

    QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.

  • CVE-2005-2925Oct 12, 2005
    risk 0.03cvss epss 0.01

    runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin.

  • CVE-2005-3180Oct 12, 2005
    risk 0.00cvss epss 0.04

    The Orinoco driver (orinoco.c) in Linux kernel 2.6.13 and earlier does not properly clear memory from a previously used packet whose length is increased, which allows remote attackers to obtain sensitive information.

  • CVE-2005-3181Oct 12, 2005
    risk 0.00cvss epss 0.01

    The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows…

  • CVE-2005-3119Oct 12, 2005
    risk 0.00cvss epss 0.00

    Memory leak in the request_key_auth_destroy function in request_key_auth in Linux kernel 2.6.10 up to 2.6.13 allows local users to cause a denial of service (memory consumption) via a large number of authorization token keys.

  • CVE-2005-3179Oct 12, 2005
    risk 0.00cvss epss 0.00

    drm.c in Linux kernel 2.6.10 to 2.6.13 creates a debug file in sysfs with world-readable and world-writable permissions, which allows local users to enable DRM debugging and obtain sensitive information.

  • CVE-2005-2337Oct 7, 2005
    risk 0.00cvss epss 0.03

    Ruby 1.6.x up to 1.6.8, 1.8.x up to 1.8.2, and 1.9.0 development up to 2005-09-01 allows attackers to bypass safe level and taint flag protections and execute disallowed code when Ruby processes a program through standard input (stdin).

  • CVE-2005-1764Oct 7, 2005
    risk 0.00cvss epss 0.00

    Linux 2.6.11 on 64-bit x86 (x86_64) platforms does not use a guard page for the 47-bit address page to protect against an AMD K8 bug, which allows local users to cause a denial of service.

  • CVE-2005-2104Oct 7, 2005
    risk 0.00cvss epss 0.00

    sysreport before 1.3.7 allows local users to obtain sensitive information via a symlink attack on a temporary directory.

  • CVE-2005-3178Oct 7, 2005
    risk 0.00cvss epss 0.04

    Buffer overflow in xloadimage 4.1 and earlier, and xli, might allow user-assisted attackers to execute arbitrary code via a long title name in a NIFF file, which triggers the overflow during (1) zoom, (2) reduce, or (3) rotate operations.

  • CVE-2005-3118Oct 6, 2005
    risk 0.00cvss epss 0.01

    Mason before 1.0.0 does not install the init script after the user uses Mason to configure a firewall, which causes the system to run without a firewall after a reboot.

  • CVE-2005-3157Oct 6, 2005
    risk 0.03cvss epss 0.04

    SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_send parameter, a different vulnerability than CVE-2005-3158 and CVE-2005-3159.

  • CVE-2005-3158Oct 6, 2005
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands via the (1) pm_email_notify and (2) pm_save_sent parameters, a different vulnerability than CVE-2005-3157 and CVE-2005-3159.

  • CVE-2005-3159Oct 6, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.

  • CVE-2005-3160Oct 6, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in photogallery.php in PHP-Fusion allow remote attackers to execute arbitrary SQL commands via the (1) album and (2) photo parameters.

  • CVE-2005-3161Oct 6, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the activate parameter in register.php and (2) the cat_id parameter in faq.php.

  • CVE-2005-3163Oct 6, 2005
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in Polipo 0.9.8 and earlier allows attackers to read files outside of the web root.

  • CVE-2005-3164Oct 6, 2005
    risk 0.01cvss epss 0.07

    The AJP connector in Apache Tomcat 4.0.1 through 4.0.6 and 4.1.0 through 4.1.36, as used in Hitachi Cosminexus Application Server and standalone, does not properly handle when a connection is broken before request body data is sent in a POST request, which can lead to an…

  • CVE-2005-3165Oct 6, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) tags or (2) Extension or sections that "bypass HTML style attribute restrictions" that are intended to protect…

  • CVE-2005-3166Oct 6, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in "edit submission handling" for MediaWiki 1.4.x before 1.4.10 and 1.3.x before 1.3.16 allows remote attackers to cause a denial of service (corruption of the previous submission) via a crafted URL.

  • CVE-2005-3167Oct 6, 2005
    risk 0.00cvss epss 0.01

    Incomplete blacklist vulnerability in MediaWiki before 1.4.11 does not properly remove certain CSS inputs (HTML inline style attributes) that are processed as active content by Internet Explorer, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

  • CVE-2005-3168Oct 6, 2005
    risk 0.00cvss epss 0.04

    The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions…

  • CVE-2005-3169Oct 6, 2005
    risk 0.00cvss epss 0.03

    Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to…

  • CVE-2005-3170MedOct 6, 2005
    risk 0.33cvss 5.0epss 0.01

    The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a…

  • CVE-2005-3171Oct 6, 2005
    risk 0.00cvss epss 0.01

    Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administrators to believe…

  • CVE-2005-3172Oct 6, 2005
    risk 0.00cvss epss 0.05

    The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could prevent the string from being null terminated and lead to data corruption or enable…

  • CVE-2005-3173Oct 6, 2005
    risk 0.00cvss epss 0.01

    Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intended restrictions.

  • CVE-2005-3174Oct 6, 2005
    risk 0.00cvss epss 0.01

    Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.

  • CVE-2005-3175Oct 6, 2005
    risk 0.00cvss epss 0.01

    Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator.

  • CVE-2005-3176Oct 6, 2005
    risk 0.00cvss epss 0.04

    Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.

  • CVE-2005-3177Oct 6, 2005
    risk 0.00cvss epss 0.01

    CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table contains a large number of files or if the descriptors do not satisfy certain…

  • CVE-2005-3154Oct 5, 2005
    risk 0.00cvss epss 0.04

    Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.