VYPR

CVEs

378,504 total · page 7348 of 7,571

  • CVE-2005-1316May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

  • CVE-2005-1318May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Horde Forwards E-Mail Forwarding Manager before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

  • CVE-2005-1319May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

  • CVE-2005-1320May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

  • CVE-2005-1321May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

  • CVE-2005-1322May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Horde Nag Task List Manager before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

  • CVE-2005-1323May 2, 2005
    risk 0.08cvss epss 0.63

    Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long USER command.

  • CVE-2005-1324May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in index.php for phpMyVisites allow remote attackers to inject arbitrary web script or HTML via the (1) part, (2) per, or (3) site parameters.

  • CVE-2005-1325May 2, 2005
    risk 0.03cvss epss 0.03

    set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.

  • CVE-2005-1326May 2, 2005
    risk 0.00cvss epss 0.02

    Buffer overflow in VooDoo cIRCle BOTNET before 1.0.33 allows remote authenticated attackers to cause a denial of service (client crash) via a crafted packet.

  • CVE-2005-1327May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid parameter.

  • CVE-2005-1328May 2, 2005
    risk 0.00cvss epss 0.02

    OneWorldStore allows remote attackers to cause a denial of service (application crash) via a direct request to owConnections/chksettings.asp.

  • CVE-2005-1329May 2, 2005
    risk 0.03cvss epss 0.03

    owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parameter.

  • CVE-2005-1344May 2, 2005
    risk 0.00cvss epss 0.29

    Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges,…

  • CVE-2005-1345May 2, 2005
    risk 0.00cvss epss 0.02

    Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator.

  • CVE-2005-1346May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domino NT 3.1.1.87, and Mail Security for Exchange 4.5.4.743, when running on…

  • CVE-2005-1347May 2, 2005
    risk 0.00cvss epss 0.05

    ** UNVERIFIABLE ** NOTE: this issue describes a problem that can not be independently verified as of 20050421. Adobe Acrobat reader (AcroRd32.exe) 6.0 and earlier allows remote attackers to cause a denial of service ("Invalid-ID-Handle-Error" error) and modify memory beginning…

  • CVE-2005-1348May 2, 2005
    risk 0.09cvss epss 0.73

    Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute arbitrary code via a long HTTP Authorization header.

  • CVE-2005-1349May 2, 2005
    risk 0.04cvss epss 0.13

    Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a malformed parameter to a read operation.

  • CVE-2005-1350May 2, 2005
    risk 0.00cvss epss 0.02

    The ad.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

  • CVE-2005-1351May 2, 2005
    risk 0.00cvss epss 0.03

    The ad.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

  • CVE-2005-1352May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the ad.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.

  • CVE-2005-1353May 2, 2005
    risk 0.00cvss epss 0.01

    The forum.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.

  • CVE-2005-1354May 2, 2005
    risk 0.00cvss epss 0.02

    The forum.pl script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

  • CVE-2005-1355May 2, 2005
    risk 0.00cvss epss 0.01

    includer.cgi in The Includer allows remote attackers to read arbitrary files via a full pathname in the argument, a similar vulnerability to CVE-2005-0801.

  • CVE-2005-1356May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in includer.cgi script in The Includer allows remote attackers to inject arbitrary web script or HTML via the argument.

  • CVE-2005-1357May 2, 2005
    risk 0.00cvss epss 0.01

    text.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

  • CVE-2005-1358May 2, 2005
    risk 0.00cvss epss 0.02

    text.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

  • CVE-2005-1359May 2, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in text.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.

  • CVE-2005-1360May 2, 2005
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP code by modifying the path_prefix parameter to reference a URL on a remote web server that contains the code.

  • CVE-2005-1361May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in MetaCart e-Shop 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter in product.asp or (2) strCatalog_NAME parameter to productsByCategory.asp.

  • CVE-2005-1362May 2, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in MetaCart 2.0 for Paypal allow remote attackers to execute arbitrary SQL commands via the (1) intProdID parameter to product.asp, (2) intCatalogID or (3) strSubCatalogID parameters to productsByCategory.asp, (4) chkText, (5) strText, (6)…

  • CVE-2005-1363May 2, 2005
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in MetaCart 2.0 for PayFlow allow remote attackers to execute arbitrary commands via (1) intCatalogID, (2) strSubCatalogID, or (3) strSubCatalog_NAME parameter to productsByCategory.asp, (4) curCatalogID, (5) strSubCatalog_NAME, (6)…

  • CVE-2005-1364May 2, 2005
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in MetaBid Auctions allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password fields in logIn.asp, or (3) intAuctionID parameter to item.asp.

  • CVE-2005-1368May 2, 2005
    risk 0.00cvss epss 0.00

    The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP.

  • CVE-2005-1369May 2, 2005
    risk 0.00cvss epss 0.00

    The (1) it87 and (2) via686a drivers in I2C for Linux 2.6.x before 2.6.11.8, and 2.6.12 before 2.6.12-rc2, create the sysfs "alarms" file with write permissions, which allows local users to cause a denial of service (CPU consumption) by attempting to write to the file, which…

  • CVE-2005-1063Apr 29, 2005
    risk 0.00cvss epss 0.02

    The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consumption) via certain attacks that force the product to "compute unexpected…

  • CVE-2004-1342Apr 27, 2005
    risk 0.00cvss epss 0.02

    CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.

  • CVE-2004-1487Apr 27, 2005
    risk 0.00cvss epss 0.02

    wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.

  • CVE-2004-1488Apr 27, 2005
    risk 0.04cvss epss 0.12

    wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.

  • CVE-2005-0019Apr 27, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.

  • CVE-2005-0085Apr 27, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.

  • CVE-2005-0087Apr 27, 2005
    risk 0.00cvss epss 0.00

    The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.

  • CVE-2005-0159Apr 27, 2005
    risk 0.00cvss epss 0.00

    The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

  • CVE-2005-0206Apr 27, 2005
    risk 0.00cvss epss 0.03

    The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.

  • CVE-2005-0229Apr 27, 2005
    risk 0.04cvss epss 0.08

    CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.

  • CVE-2005-0412Apr 27, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter.

  • CVE-2005-0413Apr 27, 2005
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. …

  • CVE-2005-0414Apr 27, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.

  • CVE-2005-0415Apr 27, 2005
    risk 0.00cvss epss 0.02

    Multiple memory leaks in the MQL parser in Emdros before 1.1.22 allow remote attackers to cause a denial of service (memory consumption) via malformed MQL statements.