| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-1518 | 0.00 | — | 0.00 | May 11, 2005 | Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500. | |||
| CVE-2005-1519 | 0.02 | — | 0.02 | May 11, 2005 | Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups. | |||
| CVE-2005-1557 | 0.00 | — | 0.01 | May 11, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message. | |||
| CVE-2005-1558 | 0.00 | — | 0.02 | May 11, 2005 | The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie. | |||
| CVE-2005-1559 | 0.00 | — | 0.04 | May 11, 2005 | The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi. | |||
| CVE-2005-1560 | 0.00 | — | 0.04 | May 11, 2005 | The SSH module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via shell metacharacters in arguments to certain commands, as demonstrated using ping and traceroute. | |||
| CVE-2005-1561 | 0.04 | — | 0.04 | May 11, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter. | |||
| CVE-2005-1562 | 0.00 | — | 0.02 | May 11, 2005 | Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to… | |||
| CVE-2005-1572 | 0.00 | — | 0.02 | May 11, 2005 | ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083. | |||
| CVE-2005-1573 | 0.00 | — | 0.01 | May 11, 2005 | SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter. | |||
| CVE-2005-1580 | 0.00 | — | 0.03 | May 11, 2005 | users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code. | |||
| CVE-2005-1585 | 0.00 | — | 0.01 | May 11, 2005 | Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory. | |||
| CVE-2005-1588 | 0.00 | — | 0.01 | May 11, 2005 | SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be… | |||
| CVE-2005-0039 | 0.00 | — | 0.04 | May 10, 2005 | Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause… | |||
| CVE-2005-1555 | 0.00 | — | 0.01 | May 10, 2005 | Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page. | |||
| CVE-2005-1476 | 0.07 | — | 0.17 | May 9, 2005 | Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477. | |||
| CVE-2005-1477 | 0.06 | — | 0.15 | May 9, 2005 | The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities… | |||
| CVE-2005-1399 | 0.00 | — | 0.00 | May 6, 2005 | FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver. | |||
| CVE-2005-1400 | 0.00 | — | 0.00 | May 6, 2005 | The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values. | |||
| CVE-2005-1406 | 0.00 | — | 0.00 | May 6, 2005 | The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory. | |||
| CVE-2005-1471 | 0.00 | — | 0.03 | May 6, 2005 | Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data. | |||
| CVE-2005-0918 | 0.00 | — | 0.02 | May 5, 2005 | The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page… | |||
| CVE-2005-1453 | 0.00 | — | 0.01 | May 5, 2005 | fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers. | |||
| CVE-2005-1456 | 0.00 | — | 0.02 | May 5, 2005 | Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort). | |||
| CVE-2005-1457 | 0.00 | — | 0.02 | May 5, 2005 | Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash). | |||
| CVE-2005-1458 | 0.00 | — | 0.02 | May 5, 2005 | Multiple unknown "other problems" in the KINK dissector in Ethereal before 0.10.11 have unknown impact and attack vectors. | |||
| CVE-2005-1459 | 0.00 | — | 0.02 | May 5, 2005 | Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error). | |||
| CVE-2005-1460 | 0.00 | — | 0.02 | May 5, 2005 | Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length. | |||
| CVE-2005-1461 | 0.04 | — | 0.07 | May 5, 2005 | Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in… | |||
| CVE-2005-1462 | 0.00 | — | 0.03 | May 5, 2005 | Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code. | |||
| CVE-2005-1463 | 0.00 | — | 0.03 | May 5, 2005 | Multiple format string vulnerabilities in the (1) DHCP and (2) ANSI A dissectors in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code. | |||
| CVE-2005-1464 | 0.00 | — | 0.03 | May 5, 2005 | Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop). | |||
| CVE-2005-1465 | 0.00 | — | 0.02 | May 5, 2005 | Unknown vulnerability in the NCP dissector in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (long loop). | |||
| CVE-2005-1466 | 0.00 | — | 0.02 | May 5, 2005 | Unknown vulnerability in the DICOM dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (large memory allocation) via unknown vectors. | |||
| CVE-2005-1467 | 0.00 | — | 0.02 | May 5, 2005 | Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors. | |||
| CVE-2005-1468 | 0.00 | — | 0.02 | May 5, 2005 | Multiple unknown vulnerabilities in the (1) WSP, (2) Q.931, (3) H.245, (4) KINK, (5) MGCP, (6) RPC, (7) SMBMailslot, and (8) SMB NETLOGON dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) via unknown vectors that lead to a null… | |||
| CVE-2005-1469 | 0.00 | — | 0.02 | May 5, 2005 | Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer. | |||
| CVE-2005-1470 | 0.04 | — | 0.05 | May 5, 2005 | Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors. | |||
| CVE-2005-0594 | 0.00 | — | 0.01 | May 4, 2005 | Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code. | |||
| CVE-2005-0676 | 0.00 | — | 0.01 | May 4, 2005 | index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability. | |||
| CVE-2005-1194 | 0.00 | — | 0.01 | May 4, 2005 | Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287. | |||
| CVE-2005-1330 | 0.00 | — | 0.00 | May 4, 2005 | AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception. | |||
| CVE-2005-1331 | 0.00 | — | 0.02 | May 4, 2005 | The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain… | |||
| CVE-2005-1332 | 0.00 | — | 0.02 | May 4, 2005 | Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory. | |||
| CVE-2005-1333 | 0.03 | — | 0.07 | May 4, 2005 | Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files. | |||
| CVE-2005-1335 | 0.00 | — | 0.01 | May 4, 2005 | Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner." | |||
| CVE-2005-1336 | 0.00 | — | 0.01 | May 4, 2005 | Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable. | |||
| CVE-2005-1337 | 0.00 | — | 0.01 | May 4, 2005 | Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI. | |||
| CVE-2005-1338 | 0.00 | — | 0.00 | May 4, 2005 | Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext. | |||
| CVE-2005-1339 | 0.00 | — | 0.01 | May 4, 2005 | lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name. |
- CVE-2005-1518May 11, 2005risk 0.00cvss —epss 0.00
Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.
- CVE-2005-1519May 11, 2005risk 0.02cvss —epss 0.02
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.
- CVE-2005-1557May 11, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.
- CVE-2005-1558May 11, 2005risk 0.00cvss —epss 0.02
The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie.
- CVE-2005-1559May 11, 2005risk 0.00cvss —epss 0.04
The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi.
- CVE-2005-1560May 11, 2005risk 0.00cvss —epss 0.04
The SSH module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via shell metacharacters in arguments to certain commands, as demonstrated using ping and traceroute.
- CVE-2005-1561May 11, 2005risk 0.04cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in post.asp in MaxWebPortal 1.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mod, (2) M, or (3) type parameter.
- CVE-2005-1562May 11, 2005risk 0.00cvss —epss 0.02
Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to…
- CVE-2005-1572May 11, 2005risk 0.00cvss —epss 0.02
ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083.
- CVE-2005-1573May 11, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in admin_login.asp for ASP Virtual News Manager allows remote attackers to execute arbitrary SQL commands via the password parameter.
- CVE-2005-1580May 11, 2005risk 0.00cvss —epss 0.03
users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.
- CVE-2005-1585May 11, 2005risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.
- CVE-2005-1588May 11, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and therefore can not be…
- CVE-2005-0039May 10, 2005risk 0.00cvss —epss 0.04
Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in ways that cause…
- CVE-2005-1555May 10, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.
- CVE-2005-1476May 9, 2005risk 0.07cvss —epss 0.17
Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.
- CVE-2005-1477May 9, 2005risk 0.06cvss —epss 0.15
The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities…
- CVE-2005-1399May 6, 2005risk 0.00cvss —epss 0.00
FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.
- CVE-2005-1400May 6, 2005risk 0.00cvss —epss 0.00
The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.
- CVE-2005-1406May 6, 2005risk 0.00cvss —epss 0.00
The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.
- CVE-2005-1471May 6, 2005risk 0.00cvss —epss 0.03
Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.
- CVE-2005-0918May 5, 2005risk 0.00cvss —epss 0.02
The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page…
- CVE-2005-1453May 5, 2005risk 0.00cvss —epss 0.01
fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers.
- CVE-2005-1456May 5, 2005risk 0.00cvss —epss 0.02
Multiple unknown vulnerabilities in the (1) DHCP and (2) Telnet dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (abort).
- CVE-2005-1457May 5, 2005risk 0.00cvss —epss 0.02
Multiple unknown vulnerabilities in the (1) AIM, (2) LDAP, (3) FibreChannel, (4) GSM_MAP, (5) SRVLOC, and (6) NTLMSSP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash).
- CVE-2005-1458May 5, 2005risk 0.00cvss —epss 0.02
Multiple unknown "other problems" in the KINK dissector in Ethereal before 0.10.11 have unknown impact and attack vectors.
- CVE-2005-1459May 5, 2005risk 0.00cvss —epss 0.02
Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error).
- CVE-2005-1460May 5, 2005risk 0.00cvss —epss 0.02
Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.
- CVE-2005-1461May 5, 2005risk 0.04cvss —epss 0.07
Multiple buffer overflows in the (1) SIP, (2) CMIP, (3) CMP, (4) CMS, (5) CRMF, (6) ESS, (7) OCSP, (8) X.509, (9) ISIS, (10) DISTCC, (11) FCELS, (12) Q.931, (13) NCP, (14) TCAP, (15) ISUP, (16) MEGACO, (17) PKIX1Explitit, (18) PKIX_Qualified, (19) Presentation dissectors in…
- CVE-2005-1462May 5, 2005risk 0.00cvss —epss 0.03
Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.
- CVE-2005-1463May 5, 2005risk 0.00cvss —epss 0.03
Multiple format string vulnerabilities in the (1) DHCP and (2) ANSI A dissectors in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.
- CVE-2005-1464May 5, 2005risk 0.00cvss —epss 0.03
Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).
- CVE-2005-1465May 5, 2005risk 0.00cvss —epss 0.02
Unknown vulnerability in the NCP dissector in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (long loop).
- CVE-2005-1466May 5, 2005risk 0.00cvss —epss 0.02
Unknown vulnerability in the DICOM dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (large memory allocation) via unknown vectors.
- CVE-2005-1467May 5, 2005risk 0.00cvss —epss 0.02
Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.
- CVE-2005-1468May 5, 2005risk 0.00cvss —epss 0.02
Multiple unknown vulnerabilities in the (1) WSP, (2) Q.931, (3) H.245, (4) KINK, (5) MGCP, (6) RPC, (7) SMBMailslot, and (8) SMB NETLOGON dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) via unknown vectors that lead to a null…
- CVE-2005-1469May 5, 2005risk 0.00cvss —epss 0.02
Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.
- CVE-2005-1470May 5, 2005risk 0.04cvss —epss 0.05
Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.
- CVE-2005-0594May 4, 2005risk 0.00cvss —epss 0.01
Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.
- CVE-2005-0676May 4, 2005risk 0.00cvss —epss 0.01
index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.
- CVE-2005-1194May 4, 2005risk 0.00cvss —epss 0.01
Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.
- CVE-2005-1330May 4, 2005risk 0.00cvss —epss 0.00
AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.
- CVE-2005-1331May 4, 2005risk 0.00cvss —epss 0.02
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain…
- CVE-2005-1332May 4, 2005risk 0.00cvss —epss 0.02
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
- CVE-2005-1333May 4, 2005risk 0.03cvss —epss 0.07
Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.
- CVE-2005-1335May 4, 2005risk 0.00cvss —epss 0.01
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
- CVE-2005-1336May 4, 2005risk 0.00cvss —epss 0.01
Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.
- CVE-2005-1337May 4, 2005risk 0.00cvss —epss 0.01
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
- CVE-2005-1338May 4, 2005risk 0.00cvss —epss 0.00
Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.
- CVE-2005-1339May 4, 2005risk 0.00cvss —epss 0.01
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.