VYPR

CVEs

379,212 total · page 7331 of 7,585

  • CVE-2005-2192Jul 11, 2005
    risk 0.03cvss epss 0.04

    SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.

  • CVE-2005-2193Jul 11, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the user profile edit module in profile.php for PunBB 1.2.5 and earlier allows remote attackers to execute arbitrary SQL statements via the temp array, which is not initialized before it is used and prevents the attacker-supplied portions of the…

  • CVE-2005-2197Jul 11, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.

  • CVE-2005-2198Jul 11, 2005
    risk 0.00cvss epss 0.03

    PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.

  • CVE-2005-2199Jul 11, 2005
    risk 0.04cvss epss 0.10

    PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.

  • CVE-2005-2200Jul 11, 2005
    risk 0.00cvss epss 0.02

    Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.

  • CVE-2005-2201Jul 11, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.

  • CVE-2005-2202Jul 11, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2005-2203Jul 11, 2005
    risk 0.00cvss epss 0.01

    login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.

  • CVE-2005-2204Jul 11, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Computer Associates (CA) eTrust SiteMinder 5.5, when the "CSSChecking" parameter is set to "NO," allows remote attackers to inject arbitrary web script or HTML via the (1) PASSWORD or (2) BUFFER parameters to smpwservicescgi.exe, (3)…

  • CVE-2005-2205Jul 11, 2005
    risk 0.00cvss epss 0.02

    The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.

  • CVE-2005-2206Jul 11, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in CartWIZ allow remote attackers to modify SQL statements via the (1) idProduct parameter to tellAFriend.asp, (2) sortType parameter to viewSupportTickets.asp, or the id parameter to (3) updateCreditCards.asp or (4) deleteCreditCards.asp.

  • CVE-2005-2207Jul 11, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.

  • CVE-2005-2208Jul 11, 2005
    risk 0.03cvss epss 0.03

    PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.

  • CVE-2005-2209MedJul 11, 2005
    risk 0.36cvss 5.5epss 0.00

    Capturix ScanShare 1.06 build 50 stores sensitive information such as the password in cleartext in capturixss_cfg.ini, which is readable by local users.

  • CVE-2005-2210Jul 11, 2005
    risk 0.03cvss epss 0.04

    Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.

  • CVE-2005-2211Jul 11, 2005
    risk 0.00cvss epss 0.00

    Backup Manager 0.5.8a creates temporary files insecurely, which allows local users to conduct unauthorized file operations when a user is burning a CDR.

  • CVE-2005-2212Jul 11, 2005
    risk 0.00cvss epss 0.01

    Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository.

  • CVE-2005-2213Jul 11, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams.

  • CVE-2005-2214Jul 11, 2005
    risk 0.00cvss epss 0.00

    apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.

  • CVE-2005-2175Jul 9, 2005
    risk 0.03cvss epss 0.05

    The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

  • CVE-2005-2176Jul 9, 2005
    risk 0.03cvss epss 0.04

    Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.

  • CVE-2005-2173Jul 8, 2005
    risk 0.00cvss epss 0.01

    The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.

  • CVE-2005-2174Jul 8, 2005
    risk 0.00cvss epss 0.01

    Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.

  • CVE-2005-1841Jul 7, 2005
    risk 0.00cvss epss 0.01

    The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.

  • CVE-2005-1916MedJul 6, 2005
    risk 0.36cvss 5.5epss 0.00

    linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.

  • CVE-2005-2096Jul 6, 2005
    risk 0.00cvss epss 0.06

    zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.

  • CVE-2005-2147Jul 6, 2005
    risk 0.00cvss epss 0.01

    Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.

  • CVE-2005-2148Jul 6, 2005
    risk 0.00cvss epss 0.03

    Cacti 0.8.6e and earlier does not perform proper input validation to protect against common attacks, which allows remote attackers to execute arbitrary commands or SQL by sending a legitimate value in a POST request or cookie, then specifying the attack string in the URL, which…

  • CVE-2005-2149Jul 6, 2005
    risk 0.00cvss epss 0.02

    config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks.

  • CVE-2005-2151Jul 6, 2005
    risk 0.00cvss epss 0.01

    spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.

  • CVE-2005-2152Jul 6, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Geeklog before 1.3.11 allows remote attackers to execute arbitrary SQL commands via user comments for an article.

  • CVE-2005-2153Jul 6, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands via the ticket variable.

  • CVE-2005-2154Jul 6, 2005
    risk 0.03cvss epss 0.02

    PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter.

  • CVE-2005-2155Jul 6, 2005
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.

  • CVE-2005-2156Jul 6, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.

  • CVE-2005-2157Jul 6, 2005
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.

  • CVE-2005-2158Jul 6, 2005
    risk 0.00cvss epss 0.01

    A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845.

  • CVE-2005-2159Jul 6, 2005
    risk 0.00cvss epss 0.01

    mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request.

  • CVE-2005-2160HigJul 6, 2005
    risk 0.49cvss 7.5epss 0.02

    IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.

  • CVE-2005-2161Jul 6, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags.

  • CVE-2005-2162Jul 6, 2005
    risk 0.03cvss epss 0.02

    PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.

  • CVE-2005-2163Jul 6, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

  • CVE-2005-2164Jul 6, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

  • CVE-2005-2165Jul 6, 2005
    risk 0.00cvss epss 0.02

    read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.

  • CVE-2005-2166Jul 6, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

  • CVE-2005-2167Jul 6, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.

  • CVE-2005-2168Jul 6, 2005
    risk 0.00cvss epss 0.01

    delete.php in Plague News System 0.6 and earlier allows remote unauthenticated attackers to delete news, comments, and shoutbox posts by modifying the id parameter.

  • CVE-2005-2169Jul 6, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to…

  • CVE-2005-0360Jul 5, 2005
    risk 0.01cvss epss 0.12

    The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.