VYPR

CVEs

342,793 total · page 6587 of 6,856

  • CVE-2005-3084Sep 27, 2005
    risk 0.00cvss epss 0.01

    Buffer overflow in the TIFF library in the Photo Viewer for Sony PSP 2.0 firmware allows remote attackers to cause a denial of service via a crafted TIFF image.

  • CVE-2005-3085Sep 27, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) topic parameters.

  • CVE-2005-3086Sep 27, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in admin/about.php in contentServ 3.1 allows remote attackers to read or include arbitrary files via ".." sequences in the ctsWebsite parameter.

  • CVE-2005-3087Sep 27, 2005
    risk 0.00cvss epss 0.01

    The SecureW2 3.0 TLS implementation uses weak random number generators (rand and srand from system time) during generation of the pre-master secret (PMS), which makes it easier for attackers to guess the secret and decrypt sensitive data.

  • CVE-2005-3061Sep 27, 2005
    risk 0.00cvss epss 0.03

    Multiple stack-based buffer overflows in PowerArchiver 8.10 through 9.5 Beta 4 and Beta 5 allow remote attackers to execute arbitrary code via a long filename in a (1) ACE or (2) ARJ archive.

  • CVE-2005-3062Sep 27, 2005
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via the mode parameter.

  • CVE-2005-3063Sep 27, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in MailGust 1.9 allows remote attackers to execute arbitrary SQL commands via the email field on the password reminder page.

  • CVE-2005-3064Sep 27, 2005
    risk 0.03cvss epss 0.02

    MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or delete the message of the day (motd.txt).

  • CVE-2005-3065Sep 27, 2005
    risk 0.00cvss epss 0.02

    MultiTheftAuto 0.5 patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted command 40 that causes a -1 length to be used and triggers an out-of-bounds read.

  • CVE-2005-3066Sep 27, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver 1.x allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.

  • CVE-2005-3067Sep 27, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in perldiver.cgi in PerlDiver 2.x allows remote attackers to inject arbitrary web script or HTML via the module parameter.

  • CVE-2005-3068Sep 27, 2005
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit."

  • CVE-2005-3069Sep 27, 2005
    risk 0.00cvss epss 0.00

    xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.

  • CVE-2005-3070Sep 27, 2005
    risk 0.00cvss epss 0.00

    HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.

  • CVE-2005-3071Sep 27, 2005
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in Unix File System (UFS) on Solaris 8 and 9, when logging is enabled, allows local users to cause a denial of service ("soft hang") via certain write operations to UFS.

  • CVE-2005-3072Sep 27, 2005
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in pages/forum/submit.html in Interchange 4.9.3 up to 5.2.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

  • CVE-2005-3073Sep 27, 2005
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in Interchange 5.0.1 allows attackers 4.9.3, 5.0 before 5.0.2, and 5.2, when a catalog has been created using the (1) "mike", (2) "standard", or (3) "foundation" demo, allows attackers to inject Interchange Tag Language (ITL) elements into the…

  • CVE-2005-3074Sep 27, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.

  • CVE-2005-3075Sep 27, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Zengaia before 0.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

  • CVE-2005-3076Sep 27, 2005
    risk 0.00cvss epss 0.02

    Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid, (3) cid, or (4) m parameters to archive.php, or the (5) blogid parameter to blogadmin.php.

  • CVE-2005-3053Sep 26, 2005
    risk 0.00cvss epss 0.00

    The sys_set_mempolicy function in mempolicy.c in Linux kernel 2.6.x allows local users to cause a denial of service (kernel BUG()) via a negative first argument.

  • CVE-2005-3054Sep 26, 2005
    risk 0.00cvss epss 0.00

    fopen_wrappers.c in PHP 4.4.0, and possibly other versions, does not properly restrict access to other directories when the open_basedir directive includes a trailing slash, which allows PHP scripts in one directory to access files in other directories whose names are substrings…

  • CVE-2005-3055Sep 26, 2005
    risk 0.00cvss epss 0.00

    Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer reference.

  • CVE-2005-3059Sep 26, 2005
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-revalidate cache directive for HTTPS pages" or (2) a "display issue with cookie comment encoding."

  • CVE-2005-3045Sep 24, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field.

  • CVE-2005-3046Sep 24, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.

  • CVE-2005-3047Sep 24, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.

  • CVE-2005-3048Sep 24, 2005
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field in a request packet,…

  • CVE-2005-3049Sep 24, 2005
    risk 0.00cvss epss 0.03

    PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.

  • CVE-2005-3050Sep 24, 2005
    risk 0.00cvss epss 0.01

    PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.

  • CVE-2005-3051Sep 24, 2005
    risk 0.00cvss epss 0.06

    Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including Turbo Searcher, allows remote attackers to execute arbitrary code via a large ARJ block.

  • CVE-2005-3052Sep 24, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php.

  • CVE-2005-2701Sep 23, 2005
    risk 0.01cvss epss 0.07

    Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.

  • CVE-2005-2702Sep 23, 2005
    risk 0.00cvss epss 0.04

    Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.

  • CVE-2005-2703Sep 23, 2005
    risk 0.00cvss epss 0.02

    Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.

  • CVE-2005-2704Sep 23, 2005
    risk 0.00cvss epss 0.02

    Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.

  • CVE-2005-2705Sep 23, 2005
    risk 0.00cvss epss 0.04

    Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.

  • CVE-2005-2706Sep 23, 2005
    risk 0.00cvss epss 0.03

    Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.

  • CVE-2005-2707Sep 23, 2005
    risk 0.00cvss epss 0.02

    Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.

  • CVE-2005-3044Sep 22, 2005
    risk 0.00cvss epss 0.00

    Multiple vulnerabilities in Linux kernel before 2.6.13.2 allow local users to cause a denial of service (kernel OOPS from null dereference) via (1) fput in a 32-bit ioctl on 64-bit x86 systems or (2) sockfd_put in the 32-bit routing_ioctl function on 64-bit systems.

  • CVE-2005-3031Sep 22, 2005
    risk 0.00cvss epss 0.04

    Buffer overflow in vxFtpSrv 0.9.7 allows remote attackers to execute arbitrary code via a long USER name.

  • CVE-2005-3032Sep 22, 2005
    risk 0.00cvss epss 0.04

    Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument.

  • CVE-2005-3033Sep 22, 2005
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

  • CVE-2005-3034Sep 22, 2005
    risk 0.00cvss epss 0.02

    Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session.

  • CVE-2005-3035Sep 22, 2005
    risk 0.00cvss epss 0.02

    Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110.

  • CVE-2005-3036Sep 22, 2005
    risk 0.00cvss epss 0.00

    File Transfer Anywhere 3.01 stores sensitive password information in plaintext in the PASS value in the "File Transfer Anywhere" registry key, which allows local users to gain privileges.

  • CVE-2005-3037Sep 22, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL.

  • CVE-2005-3038Sep 22, 2005
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."

  • CVE-2005-3039Sep 22, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter.

  • CVE-2005-3040Sep 22, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter.