VYPR

CVEs

378,543 total · page 7342 of 7,571

  • CVE-2005-0829May 2, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters.

  • CVE-2005-0830May 2, 2005
    risk 0.00cvss epss 0.03

    Multiple buffer overflows in Xzabite DYNDNSUpdate 0.6.15 and earlier, including the ipcheck function in dyndnsupdate.c, allow remote attackers who spoof a dyndns.org server to execute arbitrary code via unknown vectors.

  • CVE-2005-0831May 2, 2005
    risk 0.00cvss epss 0.01

    PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.

  • CVE-2005-0832May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in PHP-Post before 0.33 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

  • CVE-2005-0833May 2, 2005
    risk 0.00cvss epss 0.01

    Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication.

  • CVE-2005-0834May 2, 2005
    risk 0.00cvss epss 0.01

    Belkin 54G (F5D7130) wireless router enables SNMP by default in a manner that allows remote attackers to obtain sensitive information.

  • CVE-2005-0835May 2, 2005
    risk 0.00cvss epss 0.01

    The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors.

  • CVE-2005-0836May 2, 2005
    risk 0.00cvss epss 0.03

    Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06 allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file.

  • CVE-2005-0837May 2, 2005
    risk 0.00cvss epss 0.02

    IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot).

  • CVE-2005-0838May 2, 2005
    risk 0.04cvss epss 0.09

    Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a long test value in an xsl:if tag, or (3) a long select value in an xsl:value-of…

  • CVE-2005-0839May 2, 2005
    risk 0.00cvss epss 0.00

    Linux kernel 2.6 before 2.6.11 does not restrict access to the N_MOUSE line discipline for a TTY, which allows local users to gain privileges by injecting mouse or keyboard events into other user sessions.

  • CVE-2005-0841May 2, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and possibly other php files in phpMyFamily 1.4.0 allows remote attackers to execute arbitrary SQL commands, as demonstrated via (1) the person…

  • CVE-2005-0842May 2, 2005
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) _i or (2) _c parameter.

  • CVE-2005-0843May 2, 2005
    risk 0.03cvss epss 0.04

    CRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the body parameter, which is included in the resulting Location header.

  • CVE-2005-0844May 2, 2005
    risk 0.00cvss epss 0.00

    Nortel VPN client 5.01 stores the cleartext password in the memory of the Extranet.exe process, which could allow local users to obtain sensitive information.

  • CVE-2005-0845May 2, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the Webmail interface in SurgeMail 2.2g3 allows remote authenticated users to write arbitrary files or directories via a .. (dot dot) in the attach_id parameter.

  • CVE-2005-0846May 2, 2005
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the email auto-reply message in SurgeMail 2.2g3 allow remote attackers to inject arbitrary web script or HTML via the (1) message subject or (2) message header field.

  • CVE-2005-0847May 2, 2005
    risk 0.03cvss epss 0.03

    Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.

  • CVE-2005-0848May 2, 2005
    risk 0.03cvss epss 0.03

    Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which…

  • CVE-2005-0849May 2, 2005
    risk 0.00cvss epss 0.02

    Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a…

  • CVE-2005-0850May 2, 2005
    risk 0.00cvss epss 0.02

    FileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS device name such as CON, NUL, COM1, LPT1, and others.

  • CVE-2005-0851May 2, 2005
    risk 0.00cvss epss 0.02

    FileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite loop) via certain file uploads or directory listings.

  • CVE-2005-0852May 2, 2005
    risk 0.03cvss epss 0.01

    Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3.

  • CVE-2005-0853May 2, 2005
    risk 0.03cvss epss 0.04

    betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a direct request to (1) dbBlogMX.mdb for versions before 3.0, or (2) Blog.mdb for versions 3.0 and later. NOTE: it was later reported that…

  • CVE-2005-0854May 2, 2005
    risk 0.03cvss epss 0.04

    betaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct request to upload.asp or (2) delete files via a direct request to myFiles.asp.

  • CVE-2005-0855May 2, 2005
    risk 0.00cvss epss 0.02

    CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8)…

  • CVE-2005-0856May 2, 2005
    risk 0.00cvss epss 0.01

    CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability.

  • CVE-2005-0857May 2, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.

  • CVE-2005-0858May 2, 2005
    risk 0.03cvss epss 0.01

    Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php.

  • CVE-2005-0859May 2, 2005
    risk 0.04cvss epss 0.11

    PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to (1) headlines.php or (2) news.php. NOTE: some sources have reported the "dir" parameter as being affected; however, this is likely a…

  • CVE-2005-0860May 2, 2005
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) display.php, or (5) displayall.php.

  • CVE-2005-0861May 2, 2005
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in DeleGate before 8.11.1 may allow attackers to cause a denial of service or execute arbitrary code, possibly due to "overflows on arrays."

  • CVE-2005-0862May 2, 2005
    risk 0.04cvss epss 0.11

    Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4)…

  • CVE-2005-0863May 2, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.

  • CVE-2005-0864May 2, 2005
    risk 0.00cvss epss 0.02

    The Boa web server, as used in Samsung ADSL Modem SMDK8947v1.2 and possibly other products, allows remote attackers to read arbitrary files via a full pathname in the HTTP request.

  • CVE-2005-0865May 2, 2005
    risk 0.00cvss epss 0.02

    Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP request to adsl.cgi.

  • CVE-2005-0866May 2, 2005
    risk 0.00cvss epss 0.00

    cdrecord before 4:2.0, when DEBUG is enabled, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2005-0867May 2, 2005
    risk 0.00cvss epss 0.00

    Integer overflow in Linux kernel 2.6 allows local users to overwrite kernel memory by writing to a sysfs file.

  • CVE-2005-0868May 2, 2005
    risk 0.00cvss epss 0.02

    AS/400 Telnet 5250 terminal emulation clients, as implemented by (1) IBM client access, (2) Bosanova, (3) PowerTerm, (4) Mochasoft, and possibly other emulations, allows malicious AS/400 servers to execute arbitrary commands via a STRPCO (Start PC Organizer) command followed by…

  • CVE-2005-0869May 2, 2005
    risk 0.00cvss epss 0.05

    phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which…

  • CVE-2005-0870May 2, 2005
    risk 0.03cvss epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) sensor_program parameter to index.php, (2) text[language], (3) text[template], or (4) hide_picklist…

  • CVE-2005-0871May 2, 2005
    risk 0.00cvss epss 0.02

    calendar_scheduler.php in Topic Calendar 1.0.1 module for phpBB, when running on a Microsoft IIS server, allows remote attackers to obtain sensitive information via invalid parameters, which reveal the path in an error message.

  • CVE-2005-0872May 2, 2005
    risk 0.04cvss epss 0.06

    Cross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to inject arbitrary web script or HTML via the start parameter.

  • CVE-2005-0873May 2, 2005
    risk 0.04cvss epss 0.11

    Multiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject arbitrary web script or HTML via the (1) desname or (2) repprod parameter.

  • CVE-2005-0874May 2, 2005
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in the (1) AIM, (2) MSN, (3) RSS, and other plug-ins for Trillian 2.0 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.

  • CVE-2005-0875May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple buffer overflows in the Yahoo plug-in for Trillian 2.0, 3.0, and 3.1 allow remote web servers to cause a denial of service (application crash) via a long string in an HTTP 1.1 response header.

  • CVE-2005-0876May 2, 2005
    risk 0.00cvss epss 0.03

    Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file.

  • CVE-2005-0877HigMay 2, 2005
    risk 0.49cvss 7.5epss 0.02

    Dnsmasq before 2.21 allows remote attackers to poison the DNS cache via answers to queries that were not made by Dnsmasq.

  • CVE-2005-0879May 2, 2005
    risk 0.04cvss epss 0.09

    PHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary PHP code via a URL in the act parameter.

  • CVE-2005-0880May 2, 2005
    risk 0.00cvss epss 0.01

    content.php in Vortex Portal allows remote attackers to obtain sensitive information via an invalid act parameter, which leaks the full pathname in a PHP error message.