| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-1038 | 0.00 | — | 0.01 | May 2, 2005 | crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235. | |||
| CVE-2005-1039 | 0.00 | — | 0.00 | May 2, 2005 | Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files. | |||
| CVE-2005-1040 | 0.00 | — | 0.00 | May 2, 2005 | Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification." | |||
| CVE-2005-1041 | 0.00 | — | 0.00 | May 2, 2005 | The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route. | |||
| CVE-2005-1042 | 0.00 | — | 0.04 | May 2, 2005 | Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count. | |||
| CVE-2005-1045 | 0.00 | — | 0.02 | May 2, 2005 | OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark. | |||
| CVE-2005-1046 | 0.00 | — | 0.05 | May 2, 2005 | Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file. | |||
| CVE-2005-1048 | 0.00 | — | 0.01 | May 2, 2005 | SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750. | |||
| CVE-2005-1049 | 0.03 | — | 0.04 | May 2, 2005 | Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced for… | |||
| CVE-2005-1050 | 0.00 | — | 0.01 | May 2, 2005 | The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote attackers to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message. | |||
| CVE-2005-1051 | 0.03 | — | 0.02 | May 2, 2005 | SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action. | |||
| CVE-2005-1052 | 0.01 | — | 0.09 | May 2, 2005 | Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses. | |||
| CVE-2005-1053 | 0.03 | — | 0.04 | May 2, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) c_code or (2) aid parameters. | |||
| CVE-2005-1054 | 0.03 | — | 0.04 | May 2, 2005 | PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code. | |||
| CVE-2005-1056 | 0.00 | — | 0.03 | May 2, 2005 | Unknown vulnerability in HP OpenView Network Node Manager (NMM) 6.2 through 6.4, and 7.01 through 7.50, allows remote attackers to cause a denial of service. | |||
| CVE-2005-1057 | 0.00 | — | 0.01 | May 2, 2005 | Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet." | |||
| CVE-2005-1058 | 0.00 | — | 0.01 | May 2, 2005 | Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2… | |||
| CVE-2005-1059 | 0.03 | — | 0.03 | May 2, 2005 | Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html. | |||
| CVE-2005-1060 | 0.00 | — | 0.02 | May 2, 2005 | Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets. | |||
| CVE-2005-1061 | 0.03 | — | 0.03 | May 2, 2005 | The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular… | |||
| CVE-2005-1062 | 0.00 | — | 0.03 | May 2, 2005 | The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods. | |||
| CVE-2005-1065 | 0.00 | — | 0.00 | May 2, 2005 | tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory. | |||
| CVE-2005-1066 | 0.00 | — | 0.00 | May 2, 2005 | Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack. | |||
| CVE-2005-1068 | 0.00 | — | 0.01 | May 2, 2005 | Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags. | |||
| CVE-2005-1069 | 0.00 | — | 0.02 | May 2, 2005 | Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to "an exploit on the Profile page." | |||
| CVE-2005-1073 | 0.04 | — | 0.08 | May 2, 2005 | Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter. | |||
| CVE-2005-1074 | 0.03 | — | 0.01 | May 2, 2005 | SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter. | |||
| CVE-2005-1075 | 0.03 | — | 0.02 | May 2, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php. | |||
| CVE-2005-1076 | 0.03 | — | 0.01 | May 2, 2005 | Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field. | |||
| CVE-2005-1079 | 0.03 | — | 0.01 | May 2, 2005 | SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |||
| CVE-2005-1080 | 0.00 | — | 0.06 | May 2, 2005 | Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file. | |||
| CVE-2005-1081 | 0.03 | — | 0.02 | May 2, 2005 | Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |||
| CVE-2005-1083 | 0.00 | — | 0.01 | May 2, 2005 | index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter. | |||
| CVE-2005-1084 | 0.00 | — | 0.01 | May 2, 2005 | SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter. | |||
| CVE-2005-1085 | 0.00 | — | 0.01 | May 2, 2005 | Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML. | |||
| CVE-2005-1086 | 0.03 | — | 0.06 | May 2, 2005 | Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header. | |||
| CVE-2005-1088 | 0.00 | — | 0.00 | May 2, 2005 | Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights. | |||
| CVE-2005-1090 | 0.00 | — | 0.02 | May 2, 2005 | Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files. | |||
| CVE-2005-1091 | 0.00 | — | 0.02 | May 2, 2005 | Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page. | |||
| CVE-2005-1092 | 0.03 | — | 0.01 | May 2, 2005 | Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges. | |||
| CVE-2005-1093 | 0.00 | — | 0.04 | May 2, 2005 | Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code. | |||
| CVE-2005-1095 | 0.03 | — | 0.02 | May 2, 2005 | Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |||
| CVE-2005-1097 | 0.03 | — | 0.01 | May 2, 2005 | Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges. | |||
| CVE-2005-1098 | 0.03 | — | 0.01 | May 2, 2005 | GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information. | |||
| CVE-2005-1100 | 0.04 | — | 0.11 | May 2, 2005 | Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog. | |||
| CVE-2005-1101 | 0.00 | — | 0.03 | May 2, 2005 | Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields. | |||
| CVE-2005-1102 | 0.00 | — | 0.03 | May 2, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post. | |||
| CVE-2005-1104 | 0.00 | — | 0.01 | May 2, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields. | |||
| CVE-2005-1105 | 0.03 | — | 0.06 | May 2, 2005 | Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header. | |||
| CVE-2005-1106 | 0.00 | — | 0.01 | May 2, 2005 | PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow. |
- CVE-2005-1038May 2, 2005risk 0.00cvss —epss 0.01
crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.
- CVE-2005-1039May 2, 2005risk 0.00cvss —epss 0.00
Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.
- CVE-2005-1040May 2, 2005risk 0.00cvss —epss 0.00
Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification."
- CVE-2005-1041May 2, 2005risk 0.00cvss —epss 0.00
The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.
- CVE-2005-1042May 2, 2005risk 0.00cvss —epss 0.04
Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count.
- CVE-2005-1045May 2, 2005risk 0.00cvss —epss 0.02
OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.
- CVE-2005-1046May 2, 2005risk 0.00cvss —epss 0.05
Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.
- CVE-2005-1048May 2, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.
- CVE-2005-1049May 2, 2005risk 0.03cvss —epss 0.04
Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced for…
- CVE-2005-1050May 2, 2005risk 0.00cvss —epss 0.01
The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote attackers to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.
- CVE-2005-1051May 2, 2005risk 0.03cvss —epss 0.02
SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.
- CVE-2005-1052May 2, 2005risk 0.01cvss —epss 0.09
Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.
- CVE-2005-1053May 2, 2005risk 0.03cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) c_code or (2) aid parameters.
- CVE-2005-1054May 2, 2005risk 0.03cvss —epss 0.04
PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code.
- CVE-2005-1056May 2, 2005risk 0.00cvss —epss 0.03
Unknown vulnerability in HP OpenView Network Node Manager (NMM) 6.2 through 6.4, and 7.01 through 7.50, allows remote attackers to cause a denial of service.
- CVE-2005-1057May 2, 2005risk 0.00cvss —epss 0.01
Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."
- CVE-2005-1058May 2, 2005risk 0.00cvss —epss 0.01
Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2…
- CVE-2005-1059May 2, 2005risk 0.03cvss —epss 0.03
Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.
- CVE-2005-1060May 2, 2005risk 0.00cvss —epss 0.02
Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets.
- CVE-2005-1061May 2, 2005risk 0.03cvss —epss 0.03
The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular…
- CVE-2005-1062May 2, 2005risk 0.00cvss —epss 0.03
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods.
- CVE-2005-1065May 2, 2005risk 0.00cvss —epss 0.00
tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.
- CVE-2005-1066May 2, 2005risk 0.00cvss —epss 0.00
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.
- CVE-2005-1068May 2, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags.
- CVE-2005-1069May 2, 2005risk 0.00cvss —epss 0.02
Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to "an exploit on the Profile page."
- CVE-2005-1073May 2, 2005risk 0.04cvss —epss 0.08
Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter.
- CVE-2005-1074May 2, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.
- CVE-2005-1075May 2, 2005risk 0.03cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.
- CVE-2005-1076May 2, 2005risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.
- CVE-2005-1079May 2, 2005risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
- CVE-2005-1080May 2, 2005risk 0.00cvss —epss 0.06
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
- CVE-2005-1081May 2, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
- CVE-2005-1083May 2, 2005risk 0.00cvss —epss 0.01
index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.
- CVE-2005-1084May 2, 2005risk 0.00cvss —epss 0.01
SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.
- CVE-2005-1085May 2, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.
- CVE-2005-1086May 2, 2005risk 0.03cvss —epss 0.06
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.
- CVE-2005-1088May 2, 2005risk 0.00cvss —epss 0.00
Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.
- CVE-2005-1090May 2, 2005risk 0.00cvss —epss 0.02
Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.
- CVE-2005-1091May 2, 2005risk 0.00cvss —epss 0.02
Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.
- CVE-2005-1092May 2, 2005risk 0.03cvss —epss 0.01
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.
- CVE-2005-1093May 2, 2005risk 0.00cvss —epss 0.04
Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code.
- CVE-2005-1095May 2, 2005risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter.
- CVE-2005-1097May 2, 2005risk 0.03cvss —epss 0.01
Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges.
- CVE-2005-1098May 2, 2005risk 0.03cvss —epss 0.01
GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information.
- CVE-2005-1100May 2, 2005risk 0.04cvss —epss 0.11
Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.
- CVE-2005-1101May 2, 2005risk 0.00cvss —epss 0.03
Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.
- CVE-2005-1102May 2, 2005risk 0.00cvss —epss 0.03
Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.
- CVE-2005-1104May 2, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields.
- CVE-2005-1105May 2, 2005risk 0.03cvss —epss 0.06
Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.
- CVE-2005-1106May 2, 2005risk 0.00cvss —epss 0.01
PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow.