VYPR

CVEs

379,397 total · page 7312 of 7,588

  • CVE-2005-3413Nov 1, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in desktop.php in eyeOS 0.8.4 allows remote attackers to inject arbitrary web script or HTML via the motd parameter.

  • CVE-2005-3414Nov 1, 2005
    risk 0.00cvss epss 0.02

    eyeOS 0.8.4 stores usrinfo.xml under the web document root with insufficient access control, which allows remote attackers to obtain user credentials.

  • CVE-2005-2739Nov 1, 2005
    risk 0.00cvss epss 0.00

    Keychain Access in Mac OS X 10.4.2 and earlier keeps a password visible even if a keychain times out while the password is being viewed, which could allow attackers with physical access to obtain the password.

  • CVE-2005-2749Nov 1, 2005
    risk 0.00cvss epss 0.00

    Unspecified vulnerability in the Finder Get Info window for Mac OS X 10.4 up to 10.4.2 causes Finder to misrepresent file and group ownership information. NOTE: it is not clear whether this issue satisfies the CVE definition of a vulnerability.

  • CVE-2005-2750Nov 1, 2005
    risk 0.00cvss epss 0.00

    Software Update in Mac OS X 10.4.2, when the user marks all updates to be ignored, exits without asking the user to reset the status of the updates, which could prevent important, security-relevant updates from being installed.

  • CVE-2005-2751Nov 1, 2005
    risk 0.00cvss epss 0.00

    memberd in Mac OS X 10.4 up to 10.4.2, in certain situations, does not quickly synchronize access control checks with changes in group membership, which could allow users to access files and other resources after they have been removed from a group.

  • CVE-2005-2752Nov 1, 2005
    risk 0.00cvss epss 0.00

    An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before reusing it, which could allow attackers to obtain sensitive information, a different vulnerability than CVE-2005-1126 and CVE-2005-1406.

  • CVE-2005-2977Nov 1, 2005
    risk 0.00cvss epss 0.00

    The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses.

  • CVE-2005-3313Nov 1, 2005
    risk 0.00cvss epss 0.04

    The IRC protocol dissector in Ethereal 0.10.13 allows remote attackers to cause a denial of service (infinite loop).

  • CVE-2005-3387Nov 1, 2005
    risk 0.00cvss epss 0.01

    The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code.

  • CVE-2005-3388Nov 1, 2005
    risk 0.07cvss epss 0.49

    Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."

  • CVE-2005-3389Nov 1, 2005
    risk 0.01cvss epss 0.06

    The parse_str function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when called with only one parameter, allows remote attackers to enable the register_globals directive via inputs that cause a request to be terminated due to the memory_limit setting, which causes PHP to set an…

  • CVE-2005-3390Nov 1, 2005
    risk 0.08cvss epss 0.66

    The RFC1867 file upload feature in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5, when register_globals is enabled, allows remote attackers to modify the GLOBALS array and bypass security protections of PHP applications via a multipart/form-data POST request with a "GLOBALS"…

  • CVE-2005-3391Nov 1, 2005
    risk 0.01cvss epss 0.07

    Multiple vulnerabilities in PHP before 4.4.1 allow remote attackers to bypass safe_mode and open_basedir restrictions via unknown attack vectors in (1) ext/curl and (2) ext/gd.

  • CVE-2005-3392Nov 1, 2005
    risk 0.01cvss epss 0.07

    Unspecified vulnerability in PHP before 4.4.1, when using the virtual function on Apache 2, allows remote attackers to bypass safe_mode and open_basedir directives.

  • CVE-2005-3393Nov 1, 2005
    risk 0.00cvss epss 0.03

    Format string vulnerability in the foreign_option function in options.c for OpenVPN 2.0.x allows remote clients to execute arbitrary code via format string specifiers in a push of the dhcp-option command option.

  • CVE-2005-3394Nov 1, 2005
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in forum.php in oaboard forum 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) channel parameter in the topics module and (2) topic parameter in the posting module.

  • CVE-2005-3395Nov 1, 2005
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter.

  • CVE-2005-3396Nov 1, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, might allow attackers to execute arbitrary code via a long command line argument.

  • CVE-2005-3397Nov 1, 2005
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Comersus BackOffice allows remote attackers to inject arbitrary web script or HTML via the error parameter to comersus_backoffice_supportError.asp. NOTE: the comersus_backoffice_message.asp/message vector is already covered by…

  • CVE-2005-3398Nov 1, 2005
    risk 0.04cvss epss 0.13

    The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.

  • CVE-2005-3399Nov 1, 2005
    risk 0.01cvss epss 0.08

    Multiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still…

  • CVE-2005-3400Nov 1, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still…

  • CVE-2005-3401Nov 1, 2005
    risk 0.00cvss epss 0.02

    Multiple interpretation error in TheHacker 5.8.4.128 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still…

  • CVE-2005-3402Nov 1, 2005
    risk 0.00cvss epss 0.01

    The SMTP client in Mozilla Thunderbird 1.0.5 BETA, 1.0.7, and possibly other versions, does not notify users when it cannot establish a secure channel with the server, which allows remote attackers to obtain authentication information without detection via a man-in-the-middle…

  • CVE-2005-3403Nov 1, 2005
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the _base_href parameter in translate.php, (2) the _base_path parameter in news.inc.php, and (3) the p parameter in…

  • CVE-2005-3404Nov 1, 2005
    risk 0.04cvss epss 0.10

    Multiple PHP file inclusion vulnerabilities in ATutor 1.4.1 through 1.5.1-pl1 allow remote attackers to include arbitrary files via the section parameter followed by a null byte (%00) in (1) body_header.inc.php and (2) print.php.

  • CVE-2005-3405Nov 1, 2005
    risk 0.04cvss epss 0.08

    ATutor 1.4.1 through 1.5.1-pl1 allows remote attackers to execute arbitrary PHP functions via a direct request to forum.inc.php with a modified addslashes parameter with either the (1) asc or (2) desc parameters set, possibly due to an eval injection vulnerability.

  • CVE-2005-3406Nov 1, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in phpESP 1.7.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2005-3407Nov 1, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in phpESP 1.7.5 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors.

  • CVE-2005-3408Nov 1, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in news.php in gCards version 1.43 allows remote attackers to execute arbitrary SQL commands via the limit parameter.

  • CVE-2005-3123Oct 30, 2005
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".." and "//" sequences are removed.

  • CVE-2005-3315Oct 30, 2005
    risk 0.03cvss epss 0.05

    Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, and (4) computerFilter…

  • CVE-2005-3363Oct 30, 2005
    risk 0.03cvss epss 0.03

    SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.

  • CVE-2005-3364Oct 30, 2005
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.

  • CVE-2005-3365Oct 30, 2005
    risk 0.00cvss epss 0.03

    Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name parameter in register.php, (2) the email parameter in lostpassword.php, (3) the year parameter in…

  • CVE-2005-3366Oct 30, 2005
    risk 0.00cvss epss 0.02

    PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue as claimed by the…

  • CVE-2005-3367Oct 30, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field.

  • CVE-2005-3368Oct 30, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

  • CVE-2005-3369Oct 30, 2005
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and possibly upload files via the (1) fileid and (2) subkatid parameters.

  • CVE-2005-3370Oct 30, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in ArcaVir 2005 package 2005-06-21 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that…

  • CVE-2005-3371Oct 30, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in AVG 7 7.0.323 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be…

  • CVE-2005-3372Oct 30, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in eTrust CA 7.0.1.4 with the 11.9.1 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe…

  • CVE-2005-3373Oct 30, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in Dr.Web 4.32b allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be…

  • CVE-2005-3374Oct 30, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in F-Prot 3.16c allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be…

  • CVE-2005-3375Oct 30, 2005
    risk 0.00cvss epss 0.02

    Multiple interpretation error in Ikarus demo version allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still…

  • CVE-2005-3376Oct 30, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in Kaspersky 5.0.372 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still…

  • CVE-2005-3377Oct 30, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in (1) McAfee Internet Security Suite 7.1.5 version 9.1.08 with the 4.4.00 engine and (2) McAfee Corporate 8.0.0 patch 10 with the 4400 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic…

  • CVE-2005-3378Oct 30, 2005
    risk 0.00cvss epss 0.02

    Multiple interpretation error in Norman 5.81 with the 5.83.02 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type…

  • CVE-2005-3379Oct 30, 2005
    risk 0.00cvss epss 0.01

    Multiple interpretation error in Trend Micro (1) PC-Cillin 2005 12.0.1244 with the 7.510.1002 engine and (2) OfficeScan 7.0 with the 7.510.1002 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is…