VYPR

CVEs

342,584 total · page 6597 of 6,852

  • CVE-2005-2258Jul 13, 2005
    risk 0.00cvss epss 0.03

    PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter.

  • CVE-2005-2259Jul 13, 2005
    risk 0.00cvss epss 0.04

    The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute…

  • CVE-2005-2260Jul 13, 2005
    risk 0.00cvss epss 0.03

    The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally…

  • CVE-2005-2261Jul 13, 2005
    risk 0.00cvss epss 0.04

    Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.

  • CVE-2005-2262Jul 13, 2005
    risk 0.04cvss epss 0.07

    Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval…

  • CVE-2005-2263Jul 13, 2005
    risk 0.00cvss epss 0.03

    The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run…

  • CVE-2005-2264Jul 13, 2005
    risk 0.00cvss epss 0.03

    Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.

  • CVE-2005-2265Jul 13, 2005
    risk 0.10cvss epss 0.68

    Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.

  • CVE-2005-2266Jul 13, 2005
    risk 0.00cvss epss 0.02

    Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as…

  • CVE-2005-2267Jul 13, 2005
    risk 0.00cvss epss 0.04

    Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the…

  • CVE-2005-2268Jul 13, 2005
    risk 0.00cvss epss 0.03

    Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing…

  • CVE-2005-2269Jul 13, 2005
    risk 0.01cvss epss 0.06

    Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary…

  • CVE-2005-2270Jul 13, 2005
    risk 0.02cvss epss 0.06

    Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.

  • CVE-2005-2271Jul 13, 2005
    risk 0.00cvss epss 0.01

    iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

  • CVE-2005-2272Jul 13, 2005
    risk 0.00cvss epss 0.02

    Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

  • CVE-2005-2273Jul 13, 2005
    risk 0.00cvss epss 0.02

    Opera 7.x and 8 before 8.01 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

  • CVE-2005-2274Jul 13, 2005
    risk 0.02cvss epss 0.10

    Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

  • CVE-2005-0564Jul 12, 2005
    risk 0.03cvss epss 0.26

    Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.

  • CVE-2005-1219Jul 12, 2005
    risk 0.09cvss epss 0.50

    Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.

  • CVE-2005-1859Jul 12, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in arshell in the Array Service (arrayd) for SGI ProPack 3 with SP 5 and 6, and SGI ProPack 4, allows local users to execute arbitrary shells as root on other hosts in the cluster or array.

  • CVE-2005-2215Jul 12, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.x before 1.4.6 and 1.5 before 1.5beta3 allows remote attackers to inject arbitrary web script or HTML via a parameter in the page move template, a different vulnerability than CVE-2005-1888.

  • CVE-2005-2216Jul 12, 2005
    risk 0.00cvss epss 0.03

    PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.

  • CVE-2005-2217Jul 12, 2005
    risk 0.00cvss epss 0.01

    Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables.

  • CVE-2005-2219Jul 12, 2005
    risk 0.03cvss epss 0.02

    Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.

  • CVE-2005-2220Jul 12, 2005
    risk 0.00cvss epss 0.01

    Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: the vendor has disputed…

  • CVE-2005-2221Jul 12, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4)…

  • CVE-2005-2222Jul 12, 2005
    risk 0.00cvss epss 0.01

    Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.

  • CVE-2005-2223Jul 12, 2005
    risk 0.00cvss epss 0.52

    Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.

  • CVE-2005-2224Jul 12, 2005
    risk 0.01cvss epss 0.18

    aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.

  • CVE-2005-2225Jul 12, 2005
    risk 0.01cvss epss 0.16

    Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation. NOTE: it has been reported that Gaim is…

  • CVE-2005-2226Jul 12, 2005
    risk 0.02cvss epss 0.13

    Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.

  • CVE-2005-2227Jul 12, 2005
    risk 0.00cvss epss 0.00

    Softiacom wMailserver 1.0 stores passwords in plaintext in the Darsite\MAILSRV\Admin key, which allows local users to gain administrator privileges.

  • CVE-2005-2228Jul 12, 2005
    risk 0.00cvss epss 0.01

    Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.

  • CVE-2005-2229Jul 12, 2005
    risk 0.03cvss epss 0.03

    Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password hashes, as demonstrated…

  • CVE-2005-2230Jul 12, 2005
    risk 0.00cvss epss 0.00

    Electronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats temporary file insecurely, which allows local users to overwrite arbitrary files.

  • CVE-2005-2231Jul 12, 2005
    risk 0.00cvss epss 0.00

    High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2005-2232Jul 12, 2005
    risk 0.03cvss epss 0.01

    Buffer overflow in invscout in IBM AIX 5.1.0 through 5.3.0 might allow local users to execute arbitrary code via a long command line argument.

  • CVE-2005-2233Jul 12, 2005
    risk 0.00cvss epss 0.00

    Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare.

  • CVE-2005-2234Jul 12, 2005
    risk 0.00cvss epss 0.01

    Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.

  • CVE-2005-2235Jul 12, 2005
    risk 0.00cvss epss 0.01

    Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.

  • CVE-2005-2236Jul 12, 2005
    risk 0.03cvss epss 0.01

    Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.

  • CVE-2005-2237Jul 12, 2005
    risk 0.00cvss epss 0.00

    Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.

  • CVE-2005-2238Jul 12, 2005
    risk 0.00cvss epss 0.01

    ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.

  • CVE-2005-2239Jul 12, 2005
    risk 0.03cvss epss 0.03

    oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters.

  • CVE-2005-2240Jul 12, 2005
    risk 0.00cvss epss 0.00

    xpvm.tcl in xpvm 1.2.5 allows local users to overwrite arbitrary files via a symlink attack on the xpvm.trace.$user temporary file.

  • CVE-2005-2241Jul 12, 2005
    risk 0.00cvss epss 0.01

    Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote attackers to cause a…

  • CVE-2005-2242Jul 12, 2005
    risk 0.04cvss epss 0.04

    Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) via crafted packets to (1) the CTI Manager (ctimgr.exe) or (2) the CallManager…

  • CVE-2005-2243Jul 12, 2005
    risk 0.00cvss epss 0.01

    Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumption) via a large number…

  • CVE-2005-2244Jul 12, 2005
    risk 0.00cvss epss 0.03

    The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memory allocation failure…

  • CVE-2005-2245Jul 12, 2005
    risk 0.00cvss epss 0.01

    Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers.