VYPR

CVEs

378,556 total · page 7341 of 7,572

  • CVE-2005-0726May 2, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in editpost.php in UBB.threads 6.0 allows remote attackers to execute arbitrary SQL commands via the Number parameter.

  • CVE-2005-0729May 2, 2005
    risk 0.00cvss epss 0.03

    Format string vulnerability in Xpand Rally 1.1.0.0 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a message.

  • CVE-2005-0730May 2, 2005
    risk 0.00cvss epss 0.03

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service via a request to a file on the floppy drive, as demonstrated using A:\a.txt.

  • CVE-2005-0732May 2, 2005
    risk 0.00cvss epss 0.02

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to obtain the full path of the web server via a request for a non-existent filename, which leaks the full path in an error message.

  • CVE-2005-0733May 2, 2005
    risk 0.00cvss epss 0.02

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to determine the existence of files via an HTTP request with a full pathname, which produces different messages whether the file exists or not.

  • CVE-2005-0734May 2, 2005
    risk 0.00cvss epss 0.02

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests.

  • CVE-2005-0735May 2, 2005
    risk 0.04cvss epss 0.08

    newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.

  • CVE-2005-0737May 2, 2005
    risk 0.03cvss epss 0.04

    Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.

  • CVE-2005-0738May 2, 2005
    risk 0.00cvss epss 0.05

    Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a…

  • CVE-2005-0739May 2, 2005
    risk 0.04cvss epss 0.08

    The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it vulnerable to buffer overflows, as demonstrated using modified length values that are not properly handled by the dissect_pdus and…

  • CVE-2005-0742May 2, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2005-0743May 2, 2005
    risk 0.00cvss epss 0.02

    The custom avatar uploading feature (uploader.php) for XOOPS 2.0.9.2 and earlier allows remote attackers to upload arbitrary PHP scripts, whose file extensions are not filtered.

  • CVE-2005-0744May 2, 2005
    risk 0.00cvss epss 0.02

    The web GUI for Novell iChain 2.2 and 2.3 SP2 and SP3 allows attackers to hijack sessions and gain administrator privileges by (1) sniffing the connection on TCP port 51100 and replaying the authentication information or (2) obtaining and replaying the PCZQX02 authentication…

  • CVE-2005-0746May 2, 2005
    risk 0.00cvss epss 0.02

    The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.

  • CVE-2005-0760May 2, 2005
    risk 0.00cvss epss 0.02

    The TIFF decoder in ImageMagick before 6.0 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file.

  • CVE-2005-0762May 2, 2005
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in the SGI parser in ImageMagick before 6.0 allows remote attackers to execute arbitrary code via a crafted SGI image file.

  • CVE-2005-0763May 2, 2005
    risk 0.00cvss epss 0.00

    Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code.

  • CVE-2005-0764May 2, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences.

  • CVE-2005-0766May 2, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the sFlow dissector in Ethereal 0.9.14 through 0.10.9 allows remote attackers to cause a denial of service (application crash).

  • CVE-2005-0768May 2, 2005
    risk 0.08cvss epss 0.60

    Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to port 2380.

  • CVE-2005-0769May 2, 2005
    risk 0.00cvss epss 0.03

    Multiple buffer overflows in OpenSLP before 1.1.5 allow remote attackers to have an unknown impact via malformed SLP packets.

  • CVE-2005-0770May 2, 2005
    risk 0.00cvss epss 0.03

    Format string vulnerability in DataRescue Interactive Disassembler and Debugger (IDA) Pro 4.7.0.830 allows remote attackers or local users to cause a denial of service (CPU consumption or application crash) and possibly execute arbitrary code via format string specifiers in a…

  • CVE-2005-0775May 2, 2005
    risk 0.00cvss epss 0.02

    The reportpost action in misc.php for PhotoPost PHP 5.0 RC3 does not limit the logging data that is sent to the administrator, which allows remote attackers to send large amounts of email to the administrator.

  • CVE-2005-0776May 2, 2005
    risk 0.03cvss epss 0.02

    adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow remote attackers to manipulate other users' photos.

  • CVE-2005-0777May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP 5.0 RC3 allow remote attackers to inject arbitrary web script or HTML via (1) the check_tags function or (2) the editbio field in the user profile.

  • CVE-2005-0778May 2, 2005
    risk 0.00cvss epss 0.01

    PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject arbitrary Javascript by uploading non-image files with an image extension such as .gif.

  • CVE-2005-0779May 2, 2005
    risk 0.03cvss epss 0.03

    PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a \ (backslash) in the username.

  • CVE-2005-0781May 2, 2005
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to pafiledb.php.

  • CVE-2005-0782May 2, 2005
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.

  • CVE-2005-0783May 2, 2005
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the filename of an attached file.

  • CVE-2005-0784May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Phorum before 5.0.15 allow remote attackers to inject arbitrary web script or HTML via (1) the subject line to follow.php or (2) the subject line in the user's personal control panel.

  • CVE-2005-0785May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in usersrecentposts in YaBB 2.0 rc1 allows remote attackers to inject arbitrary web script or HTML via the username parameter.

  • CVE-2005-0787May 2, 2005
    risk 0.00cvss epss 0.00

    Wine 20050211 and earlier creates temp files with world readable permissions and predictable file names, which allows local users to obtain sensitive information, such as passwords.

  • CVE-2005-0796May 2, 2005
    risk 0.03cvss epss 0.03

    Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by a .. (dot dot) in the vote_filename parameter, which bypasses the check by HolaCMS to ensure that the file is in the holaDB/votes directory.

  • CVE-2005-0800May 2, 2005
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the l parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2005-0720.

  • CVE-2005-0801May 2, 2005
    risk 0.00cvss epss 0.01

    Directory traversal vulnerability in includer.cgi in The Includer allows remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) a full pathname in the URL.

  • CVE-2005-0802May 2, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web script or HTML via the search parameter.

  • CVE-2005-0803May 2, 2005
    risk 0.08cvss epss 0.68

    The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile…

  • CVE-2005-0804May 2, 2005
    risk 0.03cvss epss 0.04

    Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string specifiers in the mailto field.

  • CVE-2005-0805May 2, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute arbitrary SQL commands via certain parameters that are used as global variables, as demonstrated using the imageid parameter, which is not properly…

  • CVE-2005-0806May 2, 2005
    risk 0.00cvss epss 0.02

    Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.

  • CVE-2005-0807May 2, 2005
    risk 0.00cvss epss 0.04

    Multiple buffer overflows in Cain & Abel before 2.67 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via (1) an IKE packet with a large ID field that is not properly handled by the PSK sniffer filter, (2) the HTTP…

  • CVE-2005-0808May 2, 2005
    risk 0.02cvss epss 0.23

    Apache Tomcat before 5.x allows remote attackers to cause a denial of service (application crash) via a crafted AJP12 packet to TCP port 8007.

  • CVE-2005-0809May 2, 2005
    risk 0.00cvss epss 0.01

    NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to protect the key, which allows remote attackers to obtain the key via a brute force…

  • CVE-2005-0810May 2, 2005
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in NotifyLink before 3.0 allows remote attackers to execute arbitrary SQL commands via the URL.

  • CVE-2005-0811May 2, 2005
    risk 0.00cvss epss 0.01

    The web interface in NotifyLink 3.0 does not properly restrict access to functions that have been disabled in the GUI, which allows remote authenticated users to bypass intended restrictions via a direct request to certain URLs.

  • CVE-2005-0812May 2, 2005
    risk 0.00cvss epss 0.02

    The web interface in NotifyLink 3.0 displays passwords in cleartext on the administrative page, which could allow remote attackers or local users to obtain sensitive information.

  • CVE-2005-0813May 2, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and 0.2 may allow attackers to cause a denial of service and execute arbitrary code via unknown vectors.

  • CVE-2005-0814May 2, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in lshd in Lysator LSH 1.x and 2.x before 2.0.1 allows remote attackers to cause a denial of service via unknown vectors.

  • CVE-2005-0815May 2, 2005
    risk 0.04cvss epss 0.13

    Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of service or corrupt memory via a crafted filesystem.