VYPR

CVEs

342,532 total · page 6599 of 6,851

  • CVE-2005-2112Jul 5, 2005
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.

  • CVE-2005-2113Jul 5, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger.getPost method.

  • CVE-2005-2114Jul 5, 2005
    risk 0.00cvss epss 0.02

    Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.

  • CVE-2005-2115Jul 5, 2005
    risk 0.00cvss epss 0.02

    Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-of-bounds operation.

  • CVE-2005-2134Jul 5, 2005
    risk 0.00cvss epss 0.00

    The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a…

  • CVE-2005-2135Jul 5, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.

  • CVE-2005-2136Jul 5, 2005
    risk 0.00cvss epss 0.01

    Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrary code as other users.

  • CVE-2005-2137Jul 5, 2005
    risk 0.00cvss epss 0.01

    Unknown vulnerability in NateOn Messenger 3.0 allows remote attackers to list arbitrary directories via unknown attack vectors.

  • CVE-2005-2138Jul 5, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.

  • CVE-2005-2139Jul 5, 2005
    risk 0.00cvss epss 0.01

    PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.

  • CVE-2005-2140Jul 5, 2005
    risk 0.04cvss epss 0.03

    Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename parameter.

  • CVE-2005-2141Jul 5, 2005
    risk 0.03cvss epss 0.03

    TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow.

  • CVE-2005-2142Jul 5, 2005
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in Golden FTP Server 2.60 allows remote authenticated attackers to list arbitrary directories via a "\.." (backslash dot dot) in an LS (LIST) command.

  • CVE-2005-2143Jul 5, 2005
    risk 0.01cvss epss 0.04

    Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.

  • CVE-2005-2144Jul 5, 2005
    risk 0.00cvss epss 0.00

    Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.

  • CVE-2005-2145Jul 5, 2005
    risk 0.00cvss epss 0.00

    The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an "allow" message to bypass a warning message.

  • CVE-2005-2146Jul 5, 2005
    risk 0.00cvss epss 0.00

    SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server.

  • CVE-2005-2069Jun 30, 2005
    risk 0.00cvss epss 0.03

    pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.

  • CVE-2005-0201Jun 29, 2005
    risk 0.00cvss epss 0.00

    D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.

  • CVE-2005-2054Jun 29, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in RealPlayer 10 and 10.5 (6.0.12.1040-1069) and RealOne Player v1 and v2 allows remote attackers to overwrite arbitrary files or execute arbitrary ActiveX controls via a crafted MP3 file.

  • CVE-2005-2055Jun 29, 2005
    risk 0.00cvss epss 0.01

    RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via "default settings of earlier Internet Explorer browsers".

  • CVE-2005-2056Jun 29, 2005
    risk 0.00cvss epss 0.02

    The Quantum archive decompressor in Clam AntiVirus (ClamAV) before 0.86.1 allows remote attackers to cause a denial of service (application crash) via a crafted Quantum archive.

  • CVE-2005-2057Jun 29, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to newreply.php, (5) Number,…

  • CVE-2005-2058Jun 29, 2005
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month or (6) year parameter to…

  • CVE-2005-2059MedJun 29, 2005
    risk 0.42cvss 6.5epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via a link or IMG tag.

  • CVE-2005-2060Jun 29, 2005
    risk 0.00cvss epss 0.01

    Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the Cat parameter.

  • CVE-2005-2061Jun 29, 2005
    risk 0.00cvss epss 0.01

    Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.

  • CVE-2005-2062Jun 29, 2005
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertiserstart.asp or (5)…

  • CVE-2005-2063Jun 29, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keyword field in search.asp.

  • CVE-2005-2064Jun 29, 2005
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City,…

  • CVE-2005-2065Jun 29, 2005
    risk 0.03cvss epss 0.02

    HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode parameter.

  • CVE-2005-2066Jun 29, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.

  • CVE-2005-2067Jun 29, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.

  • CVE-2005-2070Jun 29, 2005
    risk 0.00cvss epss 0.02

    The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.

  • CVE-2005-2071Jun 29, 2005
    risk 0.03cvss epss 0.01

    traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).

  • CVE-2005-2072Jun 29, 2005
    risk 0.03cvss epss 0.01

    The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.

  • CVE-2005-2073Jun 29, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.

  • CVE-2005-2074Jun 29, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.0.105 allows remote attackers to inject arbitrary web script or HTML via a news or article post, possibly involving the (1) news_body, (2) article_description, or (3) article_body parameters to submit.php.

  • CVE-2005-2075Jun 29, 2005
    risk 0.03cvss epss 0.07

    PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory…

  • CVE-2005-2076Jun 29, 2005
    risk 0.00cvss epss 0.01

    HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.

  • CVE-2005-2077Jun 29, 2005
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.

  • CVE-2005-2078Jun 29, 2005
    risk 0.03cvss epss 0.02

    BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.

  • CVE-2005-2080Jun 29, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.

  • CVE-2005-0772HigJun 28, 2005
    risk 0.50cvss 7.5epss 0.36

    VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an invalid (non-0) "Error Status"…

  • CVE-2005-1759Jun 28, 2005
    risk 0.00cvss epss 0.00

    Race condition in shtool 2.0.1 and earlier allows local users to modify or create arbitrary files via a symlink attack on temporary files after they have been created, a different vulnerability than CVE-2005-1751.

  • CVE-2005-1766Jun 28, 2005
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such as an SMIL file.

  • CVE-2005-2050Jun 28, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arbitrary memory and possibly key information from the exit server's process space.

  • CVE-2005-2051Jun 28, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev. 5484 allows remote attackers to execute arbitrary code.

  • CVE-2005-2052Jun 28, 2005
    risk 0.00cvss epss 0.02

    Heap-based buffer overflow in vidplin.dll in RealPlayer 10 and 10.5 (6.0.12.1040 through 1069), RealOne Player v1 and v2, RealPlayer 8 and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an .avi file with a modified strf structure value.

  • CVE-2005-2053Jun 28, 2005
    risk 0.00cvss epss 0.02

    Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk) in the disp parameter to index.php, which reveals the path in an error message.…