VYPR

CVEs

379,439 total · page 7310 of 7,589

  • CVE-2005-3576Nov 16, 2005
    risk 0.03cvss epss 0.03

    ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.

  • CVE-2005-3577Nov 16, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.

  • CVE-2005-3578Nov 16, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.

  • CVE-2005-3579Nov 16, 2005
    risk 0.03cvss epss 0.03

    ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.

  • CVE-2005-3580Nov 16, 2005
    risk 0.00cvss epss 0.00

    QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.

  • CVE-2005-3581Nov 16, 2005
    risk 0.00cvss epss 0.00

    GDAL before 1.3.0-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.

  • CVE-2005-3582Nov 16, 2005
    risk 0.00cvss epss 0.00

    ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.

  • CVE-2005-3583Nov 16, 2005
    risk 0.00cvss epss 0.03

    (1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on…

  • CVE-2005-3584Nov 16, 2005
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the forum parameter.

  • CVE-2005-3585Nov 16, 2005
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the forum parameter.

  • CVE-2005-3586Nov 16, 2005
    risk 0.00cvss epss 0.01

    content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the application to return an error.

  • CVE-2005-3587Nov 16, 2005
    risk 0.00cvss epss 0.02

    Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.

  • CVE-2005-3588Nov 16, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field.

  • CVE-2005-3589Nov 16, 2005
    risk 0.07cvss epss 0.53

    Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.

  • CVE-2005-3591Nov 16, 2005
    risk 0.04cvss epss 0.10

    Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFunction ActionScript call in…

  • CVE-2005-3592Nov 16, 2005
    risk 0.00cvss epss 0.01

    index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter.

  • CVE-2005-3594Nov 16, 2005
    risk 0.00cvss epss 0.01

    game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name variables.

  • CVE-2005-3595Nov 16, 2005
    risk 0.01cvss epss 0.16

    By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.

  • CVE-2005-3596Nov 16, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in ASPKnowledgebase allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password fields in adminlogin.asp.

  • CVE-2005-3527Nov 9, 2005
    risk 0.00cvss epss 0.00

    Race condition in do_coredump in signal.c in Linux kernel 2.6 allows local users to cause a denial of service by triggering a core dump in one thread while another thread has a pending SIGSTOP.

  • CVE-2005-3523Nov 7, 2005
    risk 0.04cvss epss 0.09

    Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field.

  • CVE-2005-3524Nov 7, 2005
    risk 0.05cvss epss 0.21

    Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrary code by creating a long directory name, then executing the XPWD command.

  • CVE-2005-3519Nov 6, 2005
    risk 0.04cvss epss 0.08

    Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and include arbitrary local files via the (1) INCLUDE_PATH and (2) SQUIZLIB_PATH parameters in new_upgrade_functions.php, (3) the INCLUDE_PATH parameter in…

  • CVE-2005-3520Nov 6, 2005
    risk 0.03cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web script or HTML via (1) the target_url parameter in upgrade_in_progress_backend.php, (2) the stylesheet parameter in edit_table_cell_type_wysiwyg.php, and the…

  • CVE-2005-3521Nov 6, 2005
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in resetcore.php in e107 0.617 through 0.6173 allows remote attackers to execute arbitrary SQL commands, bypass authentication, and inject HTML or script via the (1) a_name parameter or (2) user field of the login page.

  • CVE-2005-3522Nov 6, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the grDisp parameter.

  • CVE-2005-3124Nov 6, 2005
    risk 0.00cvss epss 0.00

    syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.

  • CVE-2005-3507Nov 6, 2005
    risk 0.04cvss epss 0.12

    Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_archives.php and (2) show_news.php.

  • CVE-2005-3508Nov 6, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in showGallery.php in Gallery (Galerie) 2.4 allows remote attackers to execute arbitrary SQL commands via the galid parameter.

  • CVE-2005-3509Nov 6, 2005
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.

  • CVE-2005-3510Nov 6, 2005
    risk 0.00cvss epss 0.06

    Apache Tomcat 5.5.0 to 5.5.11 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous requests to list a web directory that has a large number of files.

  • CVE-2005-3511Nov 6, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Spymac Web OS 4.0 allow remote attackers to inject arbitrary web script or HTML via (a) the blogs module, including the (1) curr parameter in index.php, (2) inspire, (3) system, or (4) title parameter in blog_newentry.php,…

  • CVE-2005-3512Nov 6, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via the t parameter in a newreply action.

  • CVE-2005-3513Nov 6, 2005
    risk 0.00cvss epss 0.01

    index.php in VUBB alpha rc1 allows remote attackers to obtain the installation path of the application via a viewforum action with the f parameter set to a single quote (').

  • CVE-2005-3514Nov 6, 2005
    risk 0.03cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Forum script allow remote attackers to inject arbitrary web script or HTML via the forumID parameter to (1) newtopic.php, (2) quote.php, (3) index.php, and (4) reply.php.

  • CVE-2005-3515Nov 6, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Topsites script allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

  • CVE-2005-3516Nov 6, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in recommend.php in Chipmunk Directory script allows remote attackers to inject arbitrary web script or HTML via the entryID parameter.

  • CVE-2005-3517Nov 6, 2005
    risk 0.00cvss epss 0.01

    Chipmunk Scripts Guestbook allows remote attackers to obtain the installation path of the script via a URL that causes an error message to be displayed, such as a URL that contains a single quote (') in the start parameter of index.php.

  • CVE-2005-3518Nov 6, 2005
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL commands via the old_searches parameter.

  • CVE-2005-2628Nov 5, 2005
    risk 0.01cvss epss 0.07

    Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.

  • CVE-2005-2753Nov 5, 2005
    risk 0.00cvss epss 0.02

    Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file that causes a sign extension of the length element in a Pascal style string.

  • CVE-2005-2754Nov 5, 2005
    risk 0.00cvss epss 0.02

    Integer overflow in Apple QuickTime before 7.0.3 allows user-assisted attackers to execute arbitrary code via a crafted MOV file with "Improper movie attributes."

  • CVE-2005-2755Nov 5, 2005
    risk 0.00cvss epss 0.02

    Apple QuickTime Player before 7.0.3 allows user-assisted attackers to cause a denial of service (crash) via a crafted file with a missing movie attribute, which leads to a null dereference.

  • CVE-2005-2756Nov 5, 2005
    risk 0.00cvss epss 0.04

    Apple QuickTime before 7.0.3 allows user-assisted attackers to overwrite memory and execute arbitrary code via a crafted PICT file that triggers an overflow during expansion.

  • CVE-2005-3303Nov 5, 2005
    risk 0.01cvss epss 0.07

    The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file.

  • CVE-2005-3500Nov 5, 2005
    risk 0.00cvss epss 0.04

    The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block.

  • CVE-2005-3501Nov 5, 2005
    risk 0.00cvss epss 0.04

    The cabd_find function in cabd.c of the libmspack library (mspack) for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted CAB file that causes cabd_find to be called with a zero length.

  • CVE-2005-3502Nov 5, 2005
    risk 0.00cvss epss 0.02

    attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.

  • CVE-2005-3503Nov 5, 2005
    risk 0.03cvss epss 0.03

    chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.

  • CVE-2005-3504Nov 5, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.