VYPR

CVEs

342,369 total · page 6607 of 6,848

  • CVE-2005-1518May 11, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.

  • CVE-2005-1519May 11, 2005
    risk 0.02cvss epss 0.02

    Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.

  • CVE-2005-1557May 11, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.

  • CVE-2005-1558May 11, 2005
    risk 0.00cvss epss 0.02

    The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie.

  • CVE-2005-1559May 11, 2005
    risk 0.00cvss epss 0.04

    The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi.

  • CVE-2005-1560May 11, 2005
    risk 0.00cvss epss 0.04

    The SSH module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via shell metacharacters in arguments to certain commands, as demonstrated using ping and traceroute.

  • CVE-2005-1561May 11, 2005
    risk 0.04cvss epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.

  • CVE-2005-1562May 11, 2005
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to…

  • CVE-2005-1572May 11, 2005
    risk 0.00cvss epss 0.02

    ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083.

  • CVE-2005-1573May 11, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.

  • CVE-2005-1580May 11, 2005
    risk 0.00cvss epss 0.03

    users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.

  • CVE-2005-1585May 11, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.

  • CVE-2005-1588May 11, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be…

  • CVE-2005-0039May 10, 2005
    risk 0.00cvss epss 0.04

    Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause…

  • CVE-2005-1555May 10, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.

  • CVE-2005-1476May 9, 2005
    risk 0.07cvss epss 0.17

    Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.

  • CVE-2005-1477May 9, 2005
    risk 0.06cvss epss 0.15

    The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities…

  • CVE-2005-1399May 6, 2005
    risk 0.00cvss epss 0.00

    FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.

  • CVE-2005-1400May 6, 2005
    risk 0.00cvss epss 0.00

    The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.

  • CVE-2005-1406May 6, 2005
    risk 0.00cvss epss 0.00

    The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.

  • CVE-2005-1471May 6, 2005
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.

  • CVE-2005-0918May 5, 2005
    risk 0.00cvss epss 0.02

    The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page…

  • CVE-2005-1453May 5, 2005
    risk 0.00cvss epss 0.01

    fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers.

  • CVE-2005-1456May 5, 2005
    risk 0.00cvss epss 0.02

    Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).

  • CVE-2005-1457May 5, 2005
    risk 0.00cvss epss 0.02

    Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).

  • CVE-2005-1458May 5, 2005
    risk 0.00cvss epss 0.02

    Multiple unknown "other problems" in the KINK dissector in Ethereal before 0.10.11 have unknown impact and attack vectors.

  • CVE-2005-1459May 5, 2005
    risk 0.00cvss epss 0.02

    Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error).

  • CVE-2005-1460May 5, 2005
    risk 0.00cvss epss 0.02

    Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.

  • CVE-2005-1461May 5, 2005
    risk 0.04cvss epss 0.07

    Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in…

  • CVE-2005-1462May 5, 2005
    risk 0.00cvss epss 0.03

    Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.

  • CVE-2005-1463May 5, 2005
    risk 0.00cvss epss 0.03

    Multiple format string vulnerabilities in the (1) DHCP and (2) ANSI A dissectors in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.

  • CVE-2005-1464May 5, 2005
    risk 0.00cvss epss 0.03

    Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).

  • CVE-2005-1465May 5, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the NCP dissector in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (long loop).

  • CVE-2005-1466May 5, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the DICOM dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (large memory allocation) via unknown vectors.

  • CVE-2005-1467May 5, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.

  • CVE-2005-1468May 5, 2005
    risk 0.00cvss epss 0.02

    Multiple unknown vulnerabilities in the (1) WSP, (2) Q.931, (3) H.245, (4) KINK, (5) MGCP, (6) RPC, (7) SMBMailslot, and (8) SMB NETLOGON dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) via unknown vectors that lead to a null…

  • CVE-2005-1469May 5, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.

  • CVE-2005-1470May 5, 2005
    risk 0.04cvss epss 0.05

    Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.

  • CVE-2005-0594May 4, 2005
    risk 0.00cvss epss 0.01

    Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.

  • CVE-2005-0676May 4, 2005
    risk 0.00cvss epss 0.01

    index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.

  • CVE-2005-1194May 4, 2005
    risk 0.00cvss epss 0.01

    Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.

  • CVE-2005-1330May 4, 2005
    risk 0.00cvss epss 0.00

    AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.

  • CVE-2005-1331May 4, 2005
    risk 0.00cvss epss 0.02

    The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain…

  • CVE-2005-1332May 4, 2005
    risk 0.00cvss epss 0.02

    Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.

  • CVE-2005-1333May 4, 2005
    risk 0.03cvss epss 0.07

    Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.

  • CVE-2005-1335May 4, 2005
    risk 0.00cvss epss 0.01

    Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."

  • CVE-2005-1336May 4, 2005
    risk 0.00cvss epss 0.01

    Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.

  • CVE-2005-1337May 4, 2005
    risk 0.00cvss epss 0.01

    Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.

  • CVE-2005-1338May 4, 2005
    risk 0.00cvss epss 0.00

    Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.

  • CVE-2005-1339May 4, 2005
    risk 0.00cvss epss 0.01

    lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.