VYPR

CVEs

378,628 total · page 7336 of 7,573

  • CVE-2005-0091May 2, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when using the hugemem kernel, allows local users to read and write to arbitrary kernel memory and gain privileges via certain syscalls.

  • CVE-2005-0118May 2, 2005
    risk 0.00cvss epss 0.00

    helvis 1.8h2_1 and earlier stores recovery files in world readable directories with world readable permissions, which allows local users to read the recovered files of other users.

  • CVE-2005-0119May 2, 2005
    risk 0.00cvss epss 0.00

    helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.

  • CVE-2005-0120May 2, 2005
    risk 0.00cvss epss 0.00

    helvis 1.8h2_1 and earlier allows local users to delete arbitrary files via the elvprsv setuid program.

  • CVE-2005-0121May 2, 2005
    risk 0.00cvss epss 0.00

    Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.

  • CVE-2005-0125May 2, 2005
    risk 0.00cvss epss 0.00

    The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which…

  • CVE-2005-0126May 2, 2005
    risk 0.00cvss epss 0.03

    ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.

  • CVE-2005-0127May 2, 2005
    risk 0.00cvss epss 0.03

    Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.

  • CVE-2005-0133May 2, 2005
    risk 0.00cvss epss 0.03

    ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.

  • CVE-2005-0135May 2, 2005
    risk 0.00cvss epss 0.00

    The unw_unwind_to_user function in unwind.c on Itanium (ia64) architectures in Linux kernel 2.6 allows local users to cause a denial of service (system crash).

  • CVE-2005-0137May 2, 2005
    risk 0.00cvss epss 0.00

    Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a "missing Itanium syscall table entry."

  • CVE-2005-0140May 2, 2005
    risk 0.00cvss epss 0.02

    Buffer overflow in PeID allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.

  • CVE-2005-0141May 2, 2005
    risk 0.00cvss epss 0.01

    Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.

  • CVE-2005-0142May 2, 2005
    risk 0.00cvss epss 0.00

    Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper…

  • CVE-2005-0144May 2, 2005
    risk 0.00cvss epss 0.01

    Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.

  • CVE-2005-0146May 2, 2005
    risk 0.00cvss epss 0.01

    Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle-click event on systems for which a middle-click performs a paste operation.

  • CVE-2005-0147May 2, 2005
    risk 0.00cvss epss 0.01

    Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.

  • CVE-2005-0148May 2, 2005
    risk 0.00cvss epss 0.01

    Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system.…

  • CVE-2005-0155May 2, 2005
    risk 0.03cvss epss 0.01

    The PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the PERLIO_DEBUG variable.

  • CVE-2005-0158May 2, 2005
    risk 0.00cvss epss 0.02

    Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via certain responses.

  • CVE-2005-0173May 2, 2005
    risk 0.03cvss epss 0.32

    squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.

  • CVE-2005-0183May 2, 2005
    risk 0.00cvss epss 0.00

    ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.

  • CVE-2005-0184May 2, 2005
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a .. (dot dot) in a get request.

  • CVE-2005-0185May 2, 2005
    risk 0.03cvss epss 0.04

    Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.

  • CVE-2005-0187May 2, 2005
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.

  • CVE-2005-0194May 2, 2005
    risk 0.00cvss epss 0.05

    Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator…

  • CVE-2005-0195May 2, 2005
    risk 0.00cvss epss 0.04

    Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.

  • CVE-2005-0196May 2, 2005
    risk 0.00cvss epss 0.04

    Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.

  • CVE-2005-0197May 2, 2005
    risk 0.00cvss epss 0.02

    Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.

  • CVE-2005-0198May 2, 2005
    risk 0.00cvss epss 0.05

    A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote…

  • CVE-2005-0199CriMay 2, 2005
    risk 0.68cvss 9.8epss 0.19

    Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a…

  • CVE-2005-0200May 2, 2005
    risk 0.00cvss epss 0.02

    TikiWiki before 1.8.5 does not properly validate files that have been uploaded to the temp directory, which could allow remote attackers to upload and execute arbitrary PHP scripts, a different vulnerability than CVE-2004-1386.

  • CVE-2005-0202May 2, 2005
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./"…

  • CVE-2005-0204May 2, 2005
    risk 0.00cvss epss 0.00

    Linux kernel before 2.6.9, when running on the AMD64 and Intel EM64T architectures, allows local users to write to privileged IO ports via the OUTS instruction.

  • CVE-2005-0205May 2, 2005
    risk 0.00cvss epss 0.00

    KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by…

  • CVE-2005-0207May 2, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.

  • CVE-2005-0208May 2, 2005
    risk 0.00cvss epss 0.03

    The HTML parsing functions in Gaim before 1.1.4 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0473.

  • CVE-2005-0209May 2, 2005
    risk 0.00cvss epss 0.03

    Netfilter in Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via crafted IP packet fragments.

  • CVE-2005-0210May 2, 2005
    risk 0.00cvss epss 0.00

    Netfilter in the Linux kernel 2.6.8.1 allows local users to cause a denial of service (memory consumption) via certain packet fragments that are reassembled twice, which causes a data structure to be allocated twice.

  • CVE-2005-0211May 2, 2005
    risk 0.02cvss epss 0.22

    Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.

  • CVE-2005-0212May 2, 2005
    risk 0.00cvss epss 0.02

    The Amp II engine as used by Gore: Ultimate Soldier 1.50 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero byte UDP packet.

  • CVE-2005-0213May 2, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in WinHKI 1.4d allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a zip file.

  • CVE-2005-0214May 2, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Simple PHP Blog (SPHPBlog) 0.3.7c allows remote attackers to read or create arbitrary files via a .. (dot dot) in the entry parameter.

  • CVE-2005-0215May 2, 2005
    risk 0.00cvss epss 0.01

    Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a large (1) height or (2) width value.

  • CVE-2005-0216May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in formmail.php in Woltlab Burning Board Lite 1.0.0, 1.0.1e, and possibly other versions, allows remote attackers to inject arbitrary web script and HTML via the userid parameter.

  • CVE-2005-0217May 2, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in index.php in Invision Community Blog allows remote attackers to execute arbitrary SQL commands via the eid parameter.

  • CVE-2005-0218May 2, 2005
    risk 0.00cvss epss 0.02

    ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.

  • CVE-2005-0219May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir…

  • CVE-2005-0220May 2, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.

  • CVE-2005-0222May 2, 2005
    risk 0.00cvss epss 0.01

    main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.