VYPR

CVEs

378,655 total · page 7334 of 7,574

  • CVE-2005-1377May 3, 2005
    risk 0.00cvss epss 0.02

    Multiple PHP remote file inclusion vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary PHP code via unknown vectors.

  • CVE-2005-1378May 3, 2005
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.

  • CVE-2005-1379May 3, 2005
    risk 0.00cvss epss 0.00

    The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.

  • CVE-2005-1380May 3, 2005
    risk 0.03cvss epss 0.05

    Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.

  • CVE-2005-1381May 3, 2005
    risk 0.05cvss epss 0.20

    Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.

  • CVE-2005-1382May 3, 2005
    risk 0.04cvss epss 0.07

    The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter.

  • CVE-2005-1383May 3, 2005
    risk 0.05cvss epss 0.31

    The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.

  • CVE-2005-1384May 3, 2005
    risk 0.03cvss epss 0.03

    Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.

  • CVE-2005-1385May 3, 2005
    risk 0.00cvss epss 0.02

    Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference.

  • CVE-2005-1386May 3, 2005
    risk 0.00cvss epss 0.01

    PHP-Nuke 7.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) ipban.php, (2) db.php, (3) lang-norwegian.php, (4) lang-indonesian.php, (5) lang-greek.php, (6) a request to Web_Links with the portuguese language (lang-portuguese.php),…

  • CVE-2005-1387May 3, 2005
    risk 0.00cvss epss 0.00

    Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing processes.

  • CVE-2005-1388May 3, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in SURVIVOR before 0.9.6 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2005-1391May 3, 2005
    risk 0.00cvss epss 0.06

    Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP header.

  • CVE-2005-1392May 3, 2005
    risk 0.00cvss epss 0.00

    The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.

  • CVE-2005-1393May 3, 2005
    risk 0.00cvss epss 0.01

    Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.

  • CVE-2005-1394May 3, 2005
    risk 0.03cvss epss 0.01

    Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.

  • CVE-2005-1395May 3, 2005
    risk 0.00cvss epss 0.01

    Buffer overflow in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier may allow local users to gain privileges via a long (1) XAPPLRESLANGPATH or (2) XAPPLRESDIR environment variable, or (3) command line argument.

  • CVE-2005-1396May 3, 2005
    risk 0.03cvss epss 0.01

    Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.

  • CVE-2005-1397May 3, 2005
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

  • CVE-2005-1398May 3, 2005
    risk 0.03cvss epss 0.03

    phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 through 4.6.4 are also affected.

  • CVE-2005-1401May 3, 2005
    risk 0.03cvss epss 0.04

    Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.

  • CVE-2005-1402May 3, 2005
    risk 0.03cvss epss 0.03

    Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is…

  • CVE-2005-1403May 3, 2005
    risk 0.03cvss epss 0.06

    Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the…

  • CVE-2005-1404May 3, 2005
    risk 0.00cvss epss 0.02

    MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.

  • CVE-2005-1405May 3, 2005
    risk 0.00cvss epss 0.00

    HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.

  • CVE-2005-1407May 3, 2005
    risk 0.00cvss epss 0.00

    Skype for Windows 1.2.0.0 to 1.2.0.46 allows local users to bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.

  • CVE-2005-1409May 3, 2005
    risk 0.00cvss epss 0.02

    PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."

  • CVE-2005-1410May 3, 2005
    risk 0.00cvss epss 0.00

    The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service…

  • CVE-2005-1411May 3, 2005
    risk 0.03cvss epss 0.01

    Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain privileges.

  • CVE-2005-1412May 3, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.

  • CVE-2005-1413May 3, 2005
    risk 0.03cvss epss 0.06

    Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username or (2) password parameters to admin_login.asp, or the (3) searchstring and possibly (4) ID parameters to default.asp.

  • CVE-2005-1414May 3, 2005
    risk 0.03cvss epss 0.01

    ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.

  • CVE-2005-1415May 3, 2005
    risk 0.08cvss epss 0.61

    Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.

  • CVE-2005-1416May 3, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.

  • CVE-2005-1417May 3, 2005
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in MaxWebPortal 2.x, 1.35, and other versions allow remote attackers to execute arbitrary SQL commands via (1) article_popular.asp, (2) arguments to dl_popular.asp, (3) arguments to links_popular.asp, (4) arguments to pic_popular.asp, (5)…

  • CVE-2005-1418May 3, 2005
    risk 0.03cvss epss 0.01

    NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.

  • CVE-2005-1419May 3, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter.

  • CVE-2005-1420May 3, 2005
    risk 0.00cvss epss 0.01

    Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space).

  • CVE-2005-1421May 3, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via ".." (dot dot) sequences in an HTTP request.

  • CVE-2005-1422May 3, 2005
    risk 0.00cvss epss 0.01

    Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to conduct administrator operations and cause a denial of service (server or camera shutdown) via a direct request to admin.html.

  • CVE-2005-1423May 3, 2005
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.

  • CVE-2005-1424May 3, 2005
    risk 0.03cvss epss 0.01

    StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.

  • CVE-2005-1425May 3, 2005
    risk 0.00cvss epss 0.02

    Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.

  • CVE-2005-1426May 3, 2005
    risk 0.00cvss epss 0.02

    Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).

  • CVE-2005-1427May 3, 2005
    risk 0.00cvss epss 0.02

    Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.

  • CVE-2005-1428May 3, 2005
    risk 0.00cvss epss 0.01

    edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.

  • CVE-2005-1429May 3, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.

  • CVE-2005-1430May 3, 2005
    risk 0.00cvss epss 0.00

    Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.

  • CVE-2005-1431May 3, 2005
    risk 0.00cvss epss 0.02

    The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.

  • CVE-2005-1433May 3, 2005
    risk 0.00cvss epss 0.01

    Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.