VYPR

CVEs

379,229 total · page 7326 of 7,585

  • CVE-2005-2483Aug 7, 2005
    risk 0.03cvss epss 0.03

    Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell services (.ks) script, which can reference functions from libraries that are used by that script.

  • CVE-2005-2484Aug 7, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in the rdb_query function for Denora IRC Stats 1.0 might allow attackers to execute arbitrary code.

  • CVE-2005-2485Aug 7, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2005-2486Aug 7, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-2005-1701.

  • CVE-2005-2487Aug 7, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Sun McData switches and directors 4300, 4500, 6064, and 6140 before E/OS 6.0.0 may allow attackers to cause a denial of service (connectivity and array access loss) via a network broadcast storm.

  • CVE-2005-2488Aug 7, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.

  • CVE-2005-2489Aug 7, 2005
    risk 0.00cvss epss 0.02

    Web Content Management News System allows remote attackers to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.

  • CVE-2005-1268Aug 5, 2005
    risk 0.01cvss epss 0.08

    Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.

  • CVE-2005-1272Aug 5, 2005
    risk 0.08cvss epss 0.66

    Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.

  • CVE-2005-1761Aug 5, 2005
    risk 0.00cvss epss 0.00

    Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function.

  • CVE-2005-1767Aug 5, 2005
    risk 0.00cvss epss 0.00

    traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).

  • CVE-2005-1854Aug 5, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in apt-cacher in Debian 3.1, related to "missing input sanitising," allows remote attackers to execute arbitrary commands on the caching server.

  • CVE-2005-2353Aug 5, 2005
    risk 0.00cvss epss 0.00

    run-mozilla.sh in Thunderbird, with debugging enabled, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2005-2359Aug 5, 2005
    risk 0.00cvss epss 0.01

    The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to establish an IPsec…

  • CVE-2005-2471Aug 5, 2005
    risk 0.00cvss epss 0.04

    pstopnm in netpbm does not properly use the "-dSAFER" option when calling Ghostscript to convert a PostScript file into a (1) PBM, (2) PGM, or (3) PNM file, which allows external user-assisted attackers to execute arbitrary commands.

  • CVE-2005-2472Aug 5, 2005
    risk 0.03cvss epss 0.05

    Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash) via a long string to SMTP (1) HELO or (2) MAIL FROM commands.

  • CVE-2005-2473Aug 5, 2005
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in ChurchInfo allow remote attackers to execute arbitrary SQL commands via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6)…

  • CVE-2005-2474Aug 5, 2005
    risk 0.00cvss epss 0.02

    ChurchInfo allows remote attackers to execute obtain sensitive information via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7) UserDelete.php, an…

  • CVE-2005-2475Aug 5, 2005
    risk 0.00cvss epss 0.00

    Race condition in Unzip 5.52 allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by Unzip after the decompression is complete.

  • CVE-2005-2476Aug 5, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.

  • CVE-2005-2477Aug 5, 2005
    risk 0.00cvss epss 0.01

    shop_display_products.php in Naxtor Shopping Cart 1.0 allows remote attackers to obtain sensitive information via a cat_id with a "'" (single quote), which reveals the path in an error message, possibly due to an SQL injection vulnerability.

  • CVE-2005-2478Aug 5, 2005
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in SilverNews 2.0.3 allows remote attackers to execute arbitrary SQL commands via the user field on the login page in the Admin control panel.

  • CVE-2005-2479Aug 5, 2005
    risk 0.03cvss epss 0.04

    Quick 'n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption) via a long USER command.

  • CVE-2005-2480Aug 5, 2005
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.

  • CVE-2005-2481Aug 5, 2005
    risk 0.00cvss epss 0.01

    ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.

  • CVE-2005-2453Aug 4, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in NetworkActiv Web Server 1.0, 2.0.0.6, 3.0.1.1, and 3.5.13, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the query string.

  • CVE-2005-2455Aug 4, 2005
    risk 0.04cvss epss 0.09

    Greasemonkey before 0.3.5 allows remote web servers to (1) read arbitrary files via a GET request to a file:// URL in the GM_xmlhttpRequest API function, (2) list installed scripts using GM_scripts, or obtain sensitive information via (3) GM_setValue and GM_getValue.

  • CVE-2005-2456MedAug 4, 2005
    risk 0.36cvss 5.5epss 0.00

    Array index overflow in the xfrm_sk_policy_insert function in xfrm_user.c in Linux kernel 2.6 allows local users to cause a denial of service (oops or deadlock) and possibly execute arbitrary code via a p->dir value that is larger than XFRM_POLICY_OUT, which is used as an index…

  • CVE-2005-1853Aug 3, 2005
    risk 0.00cvss epss 0.01

    gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.

  • CVE-2005-2132Aug 3, 2005
    risk 0.00cvss epss 0.01

    RPC portmapper (rpcbind) in SCO UnixWare 7.1.1 m5, 7.1.3 mp5, and 7.1.4 mp2 allows remote attackers or local users to cause a denial of service (lack of response) via multiple invalid portmap requests.

  • CVE-2005-2346Aug 3, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.

  • CVE-2005-2412Aug 3, 2005
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.

  • CVE-2005-2413Aug 3, 2005
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.

  • CVE-2005-2414Aug 3, 2005
    risk 0.03cvss epss 0.03

    Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, which causes part of the…

  • CVE-2005-2415Aug 3, 2005
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in Contrexx before 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) value parameter to the poll module or (2) pId parameter to the gallery module.

  • CVE-2005-2416Aug 3, 2005
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Contrexx before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) term parameter to the search module or (2) title in the blog aggregation module.

  • CVE-2005-2417Aug 3, 2005
    risk 0.00cvss epss 0.02

    Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.

  • CVE-2005-2419Aug 3, 2005
    risk 0.00cvss epss 0.02

    B-FOCuS Router 312+ allows remote attackers to bypass authentication and gain unauthorized access via a direct request to firmwarecfg.

  • CVE-2005-2420Aug 3, 2005
    risk 0.03cvss epss 0.06

    flsearch.pl in FtpLocate 2.02 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP GET request.

  • CVE-2005-2421Aug 3, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter.

  • CVE-2005-2422Aug 3, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter.

  • CVE-2005-2423Aug 3, 2005
    risk 0.00cvss epss 0.01

    Beehive Forum allows remote attackers to obtain sensitive information via (1) an invalid final_uri or sort_by parameter to index.php or a direct request to (2) admin.php, (3) attachments.inc.php, (4) banned.inc.php, (5) beehive.inc.php, (6) constants.inc.php, (7) db.inc.php, (8)…

  • CVE-2005-2424Aug 3, 2005
    risk 0.00cvss epss 0.02

    The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web interface that cause the…

  • CVE-2005-2425Aug 3, 2005
    risk 0.00cvss epss 0.05

    Stack-based buffer overflow in Ares FileShare 1.1 allows remote attackers or local users to execute arbitrary code via a (1) long history parameter in the configuration file (ares.conf) or (2) long search string.

  • CVE-2005-2426Aug 3, 2005
    risk 0.03cvss epss 0.01

    FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple connections and disconnections without using the QUIT command.

  • CVE-2005-2427Aug 3, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.

  • CVE-2005-2428Aug 3, 2005
    risk 0.09cvss epss 0.73

    Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field,…

  • CVE-2005-2429Aug 3, 2005
    risk 0.00cvss epss 0.01

    Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.

  • CVE-2005-2430Aug 3, 2005
    risk 0.00cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to detail.php, (5) the text…

  • CVE-2005-2431Aug 3, 2005
    risk 0.00cvss epss 0.01

    The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).