VYPR

CVEs

378,518 total · page 7345 of 7,571

  • CVE-2005-1038May 2, 2005
    risk 0.00cvss epss 0.01

    crontab in Vixie cron 4.1, when running with the -e option, allows local users to read the cron files of other users by changing the file being edited to a symlink. NOTE: there is insufficient information to know whether this is a duplicate of CVE-2001-0235.

  • CVE-2005-1039May 2, 2005
    risk 0.00cvss epss 0.00

    Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.

  • CVE-2005-1040May 2, 2005
    risk 0.00cvss epss 0.00

    Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification."

  • CVE-2005-1041May 2, 2005
    risk 0.00cvss epss 0.00

    The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route.

  • CVE-2005-1042May 2, 2005
    risk 0.00cvss epss 0.04

    Integer overflow in the exif_process_IFD_TAG function in exif.c in PHP before 4.3.11 may allow remote attackers to execute arbitrary code via an IFD tag that leads to a negative byte count.

  • CVE-2005-1045May 2, 2005
    risk 0.00cvss epss 0.02

    OpenText FirstClass 8.0 client does not properly sanitize strings before passing them to the Windows ShellExecute API, which allows remote attackers to execute arbitrary commands via a UNC path in a bookmark.

  • CVE-2005-1046May 2, 2005
    risk 0.00cvss epss 0.05

    Buffer overflow in the kimgio library for KDE 3.4.0 allows remote attackers to execute arbitrary code via a crafted PCX image file.

  • CVE-2005-1048May 2, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in modules.php in PostNuke 0.760 RC3 allows remote attackers to execute arbitrary SQL statements via the sid parameter. NOTE: the vendor reports that they could not reproduce the issues for 760 RC3, or for .750.

  • CVE-2005-1049May 2, 2005
    risk 0.03cvss epss 0.04

    Multiple cross-site scripting vulnerabilities in PostNuke 0.760-RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) module parameter to admin.php or (2) op parameter to user.php. NOTE: the vendor reports that certain issues could not be reproduced for…

  • CVE-2005-1050May 2, 2005
    risk 0.00cvss epss 0.01

    The modload op in the Reviews module for PostNuke 0.760-RC3 allows remote attackers to obtain sensitive information via an invalid id parameter, which reveals the path in a PHP error message.

  • CVE-2005-1051May 2, 2005
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in profile.php in PunBB 1.2.4 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a change_email action.

  • CVE-2005-1052May 2, 2005
    risk 0.01cvss epss 0.09

    Microsoft Outlook 2003 and Outlook Web Access (OWA) 2003 do not properly display comma separated addresses in the From field in an e-mail message, which could allow remote attackers to spoof e-mail addresses.

  • CVE-2005-1053May 2, 2005
    risk 0.03cvss epss 0.04

    Multiple cross-site scripting (XSS) vulnerabilities in orderwiz.php in ModernBill 4.3.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) c_code or (2) aid parameters.

  • CVE-2005-1054May 2, 2005
    risk 0.03cvss epss 0.04

    PHP remote file inclusion vulnerability in news.php in ModernBill 4.3.0 and earlier allows remote attackers to execute arbitrary PHP code by modifying the DIR parameter to reference a URL on a remote web server that contains the code.

  • CVE-2005-1056May 2, 2005
    risk 0.00cvss epss 0.03

    Unknown vulnerability in HP OpenView Network Node Manager (NMM) 6.2 through 6.4, and 7.01 through 7.50, allows remote attackers to cause a denial of service.

  • CVE-2005-1057May 2, 2005
    risk 0.00cvss epss 0.01

    Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."

  • CVE-2005-1058May 2, 2005
    risk 0.00cvss epss 0.01

    Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2…

  • CVE-2005-1059May 2, 2005
    risk 0.03cvss epss 0.03

    Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.

  • CVE-2005-1060May 2, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets.

  • CVE-2005-1061May 2, 2005
    risk 0.03cvss epss 0.03

    The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular…

  • CVE-2005-1062May 2, 2005
    risk 0.00cvss epss 0.03

    The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods.

  • CVE-2005-1065May 2, 2005
    risk 0.00cvss epss 0.00

    tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.

  • CVE-2005-1066May 2, 2005
    risk 0.00cvss epss 0.00

    Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2005-1068May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags.

  • CVE-2005-1069May 2, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in sCssBoard 1.11 and earlier has unknown impact, related to "an exploit on the Profile page."

  • CVE-2005-1073May 2, 2005
    risk 0.04cvss epss 0.08

    Directory traversal vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to read arbitrary files via the read parameter.

  • CVE-2005-1074May 2, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php for RadScripts RadBids Gold 2 allows remote attackers to execute arbitrary SQL commands via the mode parameter.

  • CVE-2005-1075May 2, 2005
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in RadScripts RadBids Gold 2 allow remote attackers to inject arbitrary web script or HTML via (1) the farea parameter to faq.php or the (2) cat, (3) order, or (4) area parameters to index.php.

  • CVE-2005-1076May 2, 2005
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.

  • CVE-2005-1079May 2, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

  • CVE-2005-1080May 2, 2005
    risk 0.00cvss epss 0.06

    Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.

  • CVE-2005-1081May 2, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in view.php in AzDGDatingPlatinum 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

  • CVE-2005-1083May 2, 2005
    risk 0.00cvss epss 0.01

    index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.

  • CVE-2005-1084May 2, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.

  • CVE-2005-1085May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2005-1086May 2, 2005
    risk 0.03cvss epss 0.06

    Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.

  • CVE-2005-1088May 2, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.

  • CVE-2005-1090May 2, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.

  • CVE-2005-1091May 2, 2005
    risk 0.00cvss epss 0.02

    Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.

  • CVE-2005-1092May 2, 2005
    risk 0.03cvss epss 0.01

    Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.

  • CVE-2005-1093May 2, 2005
    risk 0.00cvss epss 0.04

    Buffer overflow in the PopUp Plus 2.0.3.8 plugin for Miranda IM, with "Use SmileyAdd Setting" enabled, allows remote attackers to execute arbitrary code.

  • CVE-2005-1095May 2, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in main.asp for Ocean12 Membership Manager Pro 1.x allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • CVE-2005-1097May 2, 2005
    risk 0.03cvss epss 0.01

    Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges.

  • CVE-2005-1098May 2, 2005
    risk 0.03cvss epss 0.01

    GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information.

  • CVE-2005-1100May 2, 2005
    risk 0.04cvss epss 0.11

    Format string vulnerability in the ErrorLog function in cnf.c in Greylisting daemon (GLD) 1.3 and 1.4 allows remote attackers to execute arbitrary code via format string specifiers in data that is passed directly to syslog.

  • CVE-2005-1101May 2, 2005
    risk 0.00cvss epss 0.03

    Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.

  • CVE-2005-1102May 2, 2005
    risk 0.00cvss epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in template-functions-post.php in WordPress 1.5 and earlier allow remote attackers to execute arbitrary commands via the (1) content or (2) title of the post.

  • CVE-2005-1104May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Centra 7 allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) first name, or (3) last name fields.

  • CVE-2005-1105May 2, 2005
    risk 0.03cvss epss 0.06

    Directory traversal vulnerability in the MimeBodyPart.getFileName method in JavaMail 1.3.2 allows remote attackers to write arbitrary files via a .. (dot dot) in the filename in the Content-Disposition header.

  • CVE-2005-1106May 2, 2005
    risk 0.00cvss epss 0.01

    PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow.