| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-3576 | 0.03 | — | 0.03 | Nov 16, 2005 | ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter. | |||
| CVE-2005-3577 | 0.03 | — | 0.02 | Nov 16, 2005 | Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter. | |||
| CVE-2005-3578 | 0.03 | — | 0.01 | Nov 16, 2005 | SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter. | |||
| CVE-2005-3579 | 0.03 | — | 0.03 | Nov 16, 2005 | ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring. | |||
| CVE-2005-3580 | 0.00 | — | 0.00 | Nov 16, 2005 | QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime. | |||
| CVE-2005-3581 | 0.00 | — | 0.00 | Nov 16, 2005 | GDAL before 1.3.0-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime. | |||
| CVE-2005-3582 | 0.00 | — | 0.00 | Nov 16, 2005 | ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime. | |||
| CVE-2005-3583 | 0.00 | — | 0.03 | Nov 16, 2005 | (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on… | |||
| CVE-2005-3584 | 0.03 | — | 0.01 | Nov 16, 2005 | Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the forum parameter. | |||
| CVE-2005-3585 | 0.00 | — | 0.02 | Nov 16, 2005 | SQL injection vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the forum parameter. | |||
| CVE-2005-3586 | 0.00 | — | 0.01 | Nov 16, 2005 | content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the application to return an error. | |||
| CVE-2005-3587 | 0.00 | — | 0.02 | Nov 16, 2005 | Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors. | |||
| CVE-2005-3588 | 0.00 | — | 0.01 | Nov 16, 2005 | SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field. | |||
| CVE-2005-3589 | 0.07 | — | 0.53 | Nov 16, 2005 | Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command. | |||
| CVE-2005-3591 | 0.04 | — | 0.10 | Nov 16, 2005 | Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in… | |||
| CVE-2005-3592 | 0.00 | — | 0.01 | Nov 16, 2005 | index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter. | |||
| CVE-2005-3594 | 0.00 | — | 0.01 | Nov 16, 2005 | game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name variables. | |||
| CVE-2005-3595 | 0.01 | — | 0.16 | Nov 16, 2005 | By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer. | |||
| CVE-2005-3596 | 0.00 | — | 0.01 | Nov 16, 2005 | SQL injection vulnerability in ASPKnowledgebase allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password fields in adminlogin.asp. | |||
| CVE-2005-3527 | 0.00 | — | 0.00 | Nov 9, 2005 | Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP. | |||
| CVE-2005-3523 | 0.04 | — | 0.09 | Nov 7, 2005 | Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field. | |||
| CVE-2005-3524 | 0.05 | — | 0.21 | Nov 7, 2005 | Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command. | |||
| CVE-2005-3519 | 0.04 | — | 0.08 | Nov 6, 2005 | Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in… | |||
| CVE-2005-3520 | 0.03 | — | 0.03 | Nov 6, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the target_url parameter in upgrade_in_progress_backend.php, (2) the stylesheet parameter in edit_table_cell_type_wysiwyg.php, and the… | |||
| CVE-2005-3521 | 0.00 | — | 0.02 | Nov 6, 2005 | SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page. | |||
| CVE-2005-3522 | 0.03 | — | 0.02 | Nov 6, 2005 | Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter. | |||
| CVE-2005-3124 | 0.00 | — | 0.00 | Nov 6, 2005 | syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file. | |||
| CVE-2005-3507 | 0.04 | — | 0.12 | Nov 6, 2005 | Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php. | |||
| CVE-2005-3508 | 0.03 | — | 0.01 | Nov 6, 2005 | SQL injection vulnerability in showGallery.php in Gallery (Galerie) 2.4 allows remote attackers to execute arbitrary SQL commands via the galid parameter. | |||
| CVE-2005-3509 | 0.03 | — | 0.01 | Nov 6, 2005 | Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php. | |||
| CVE-2005-3510 | 0.00 | — | 0.06 | Nov 6, 2005 | Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files. | |||
| CVE-2005-3511 | 0.00 | — | 0.01 | Nov 6, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS 4.0 allow remote attackers to inject arbitrary web script or HTML via (a) the blogs module, including the (1) curr parameter in index.php, (2) inspire, (3) system, or (4) title parameter in blog_newentry.php,… | |||
| CVE-2005-3512 | 0.03 | — | 0.02 | Nov 6, 2005 | Cross-site scripting (XSS) vulnerability in index.php in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via the t parameter in a newreply action. | |||
| CVE-2005-3513 | 0.00 | — | 0.01 | Nov 6, 2005 | index.php in VUBB alpha rc1 allows remote attackers to obtain the installation path of the application via a viewforum action with the f parameter set to a single quote ('). | |||
| CVE-2005-3514 | 0.03 | — | 0.03 | Nov 6, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the forumID parameter to (1) newtopic.php, (2) quote.php, (3) index.php, and (4) reply.php. | |||
| CVE-2005-3515 | 0.03 | — | 0.02 | Nov 6, 2005 | Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject arbitrary web script or HTML via the ID parameter. | |||
| CVE-2005-3516 | 0.03 | — | 0.02 | Nov 6, 2005 | Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter. | |||
| CVE-2005-3517 | 0.00 | — | 0.01 | Nov 6, 2005 | Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php. | |||
| CVE-2005-3518 | 0.03 | — | 0.03 | Nov 6, 2005 | SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter. | |||
| CVE-2005-2628 | 0.01 | — | 0.07 | Nov 5, 2005 | Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer. | |||
| CVE-2005-2753 | 0.00 | — | 0.02 | Nov 5, 2005 | Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string. | |||
| CVE-2005-2754 | 0.00 | — | 0.02 | Nov 5, 2005 | Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes." | |||
| CVE-2005-2755 | 0.00 | — | 0.02 | Nov 5, 2005 | Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference. | |||
| CVE-2005-2756 | 0.00 | — | 0.04 | Nov 5, 2005 | Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion. | |||
| CVE-2005-3303 | 0.01 | — | 0.07 | Nov 5, 2005 | The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file. | |||
| CVE-2005-3500 | 0.00 | — | 0.04 | Nov 5, 2005 | The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block. | |||
| CVE-2005-3501 | 0.00 | — | 0.04 | Nov 5, 2005 | The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length. | |||
| CVE-2005-3502 | 0.00 | — | 0.02 | Nov 5, 2005 | attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter. | |||
| CVE-2005-3503 | 0.03 | — | 0.03 | Nov 5, 2005 | chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges. | |||
| CVE-2005-3504 | 0.00 | — | 0.03 | Nov 5, 2005 | Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code. |
- CVE-2005-3576Nov 16, 2005risk 0.03cvss —epss 0.03
ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.
- CVE-2005-3577Nov 16, 2005risk 0.03cvss —epss 0.02
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.
- CVE-2005-3578Nov 16, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.
- CVE-2005-3579Nov 16, 2005risk 0.03cvss —epss 0.03
ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.
- CVE-2005-3580Nov 16, 2005risk 0.00cvss —epss 0.00
QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
- CVE-2005-3581Nov 16, 2005risk 0.00cvss —epss 0.00
GDAL before 1.3.0-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
- CVE-2005-3582Nov 16, 2005risk 0.00cvss —epss 0.00
ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
- CVE-2005-3583Nov 16, 2005risk 0.00cvss —epss 0.03
(1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on…
- CVE-2005-3584Nov 16, 2005risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the forum parameter.
- CVE-2005-3585Nov 16, 2005risk 0.00cvss —epss 0.02
SQL injection vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the forum parameter.
- CVE-2005-3586Nov 16, 2005risk 0.00cvss —epss 0.01
content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the application to return an error.
- CVE-2005-3587Nov 16, 2005risk 0.00cvss —epss 0.02
Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.
- CVE-2005-3588Nov 16, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field.
- CVE-2005-3589Nov 16, 2005risk 0.07cvss —epss 0.53
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.
- CVE-2005-3591Nov 16, 2005risk 0.04cvss —epss 0.10
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in…
- CVE-2005-3592Nov 16, 2005risk 0.00cvss —epss 0.01
index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter.
- CVE-2005-3594Nov 16, 2005risk 0.00cvss —epss 0.01
game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name variables.
- CVE-2005-3595Nov 16, 2005risk 0.01cvss —epss 0.16
By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.
- CVE-2005-3596Nov 16, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in ASPKnowledgebase allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password fields in adminlogin.asp.
- CVE-2005-3527Nov 9, 2005risk 0.00cvss —epss 0.00
Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP.
- CVE-2005-3523Nov 7, 2005risk 0.04cvss —epss 0.09
Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field.
- CVE-2005-3524Nov 7, 2005risk 0.05cvss —epss 0.21
Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.
- CVE-2005-3519Nov 6, 2005risk 0.04cvss —epss 0.08
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in…
- CVE-2005-3520Nov 6, 2005risk 0.03cvss —epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the target_url parameter in upgrade_in_progress_backend.php, (2) the stylesheet parameter in edit_table_cell_type_wysiwyg.php, and the…
- CVE-2005-3521Nov 6, 2005risk 0.00cvss —epss 0.02
SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.
- CVE-2005-3522Nov 6, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.
- CVE-2005-3124Nov 6, 2005risk 0.00cvss —epss 0.00
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
- CVE-2005-3507Nov 6, 2005risk 0.04cvss —epss 0.12
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.
- CVE-2005-3508Nov 6, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in showGallery.php in Gallery (Galerie) 2.4 allows remote attackers to execute arbitrary SQL commands via the galid parameter.
- CVE-2005-3509Nov 6, 2005risk 0.03cvss —epss 0.01
Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.
- CVE-2005-3510Nov 6, 2005risk 0.00cvss —epss 0.06
Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.
- CVE-2005-3511Nov 6, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS 4.0 allow remote attackers to inject arbitrary web script or HTML via (a) the blogs module, including the (1) curr parameter in index.php, (2) inspire, (3) system, or (4) title parameter in blog_newentry.php,…
- CVE-2005-3512Nov 6, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in index.php in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via the t parameter in a newreply action.
- CVE-2005-3513Nov 6, 2005risk 0.00cvss —epss 0.01
index.php in VUBB alpha rc1 allows remote attackers to obtain the installation path of the application via a viewforum action with the f parameter set to a single quote (').
- CVE-2005-3514Nov 6, 2005risk 0.03cvss —epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the forumID parameter to (1) newtopic.php, (2) quote.php, (3) index.php, and (4) reply.php.
- CVE-2005-3515Nov 6, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
- CVE-2005-3516Nov 6, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter.
- CVE-2005-3517Nov 6, 2005risk 0.00cvss —epss 0.01
Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.
- CVE-2005-3518Nov 6, 2005risk 0.03cvss —epss 0.03
SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter.
- CVE-2005-2628Nov 5, 2005risk 0.01cvss —epss 0.07
Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.
- CVE-2005-2753Nov 5, 2005risk 0.00cvss —epss 0.02
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.
- CVE-2005-2754Nov 5, 2005risk 0.00cvss —epss 0.02
Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."
- CVE-2005-2755Nov 5, 2005risk 0.00cvss —epss 0.02
Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.
- CVE-2005-2756Nov 5, 2005risk 0.00cvss —epss 0.04
Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.
- CVE-2005-3303Nov 5, 2005risk 0.01cvss —epss 0.07
The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.
- CVE-2005-3500Nov 5, 2005risk 0.00cvss —epss 0.04
The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block.
- CVE-2005-3501Nov 5, 2005risk 0.00cvss —epss 0.04
The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length.
- CVE-2005-3502Nov 5, 2005risk 0.00cvss —epss 0.02
attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.
- CVE-2005-3503Nov 5, 2005risk 0.03cvss —epss 0.03
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.
- CVE-2005-3504Nov 5, 2005risk 0.00cvss —epss 0.03
Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.