VYPR

CVEs

378,502 total · page 7349 of 7,571

  • CVE-2005-0419Apr 27, 2005
    risk 0.03cvss epss 0.04

    Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.

  • CVE-2005-0420Apr 27, 2005
    risk 0.05cvss epss 0.26

    Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.

  • CVE-2005-0421Apr 27, 2005
    risk 0.03cvss epss 0.01

    DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.

  • CVE-2005-0422Apr 27, 2005
    risk 0.03cvss epss 0.01

    DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.

  • CVE-2005-0423Apr 27, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.

  • CVE-2005-0424Apr 27, 2005
    risk 0.00cvss epss 0.01

    Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.

  • CVE-2005-1270Apr 26, 2005
    risk 0.00cvss epss 0.00

    The (1) check_update.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.

  • CVE-2005-1274Apr 26, 2005
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter.

  • CVE-2005-1281Apr 26, 2005
    risk 0.00cvss epss 0.02

    Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.

  • CVE-2005-0684Apr 25, 2005
    risk 0.08cvss epss 0.69

    Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is…

  • CVE-2005-1275Apr 25, 2005
    risk 0.04cvss epss 0.14

    Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.

  • CVE-2005-1295Apr 25, 2005
    risk 0.00cvss epss 0.01

    include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

  • CVE-2005-1296Apr 25, 2005
    risk 0.00cvss epss 0.02

    include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

  • CVE-2005-1297Apr 25, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.

  • CVE-2005-1298Apr 25, 2005
    risk 0.00cvss epss 0.01

    The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.

  • CVE-2005-1299Apr 25, 2005
    risk 0.00cvss epss 0.03

    The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.

  • CVE-2005-1300Apr 25, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.

  • CVE-2005-1317Apr 25, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.

  • CVE-2005-1246Apr 24, 2005
    risk 0.04cvss epss 0.07

    Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format string specifiers that are not properly handled in a syslog call.

  • CVE-2005-1294Apr 24, 2005
    risk 0.03cvss epss 0.01

    The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.

  • CVE-2005-1303Apr 24, 2005
    risk 0.00cvss epss 0.01

    The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.

  • CVE-2005-1312Apr 24, 2005
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.

  • CVE-2005-1287Apr 23, 2005
    risk 0.03cvss epss 0.02

    Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.

  • CVE-2005-1291Apr 23, 2005
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in CartWIZ ASP Cart allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) addToCart.asp or (2) productDetails.asp, the (3) priceFrom, (4) idCategory, or (5) priceTo parameter to searchResults.asp, or…

  • CVE-2005-1310Apr 23, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

  • CVE-2005-0754Apr 22, 2005
    risk 0.00cvss epss 0.03

    Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.

  • CVE-2005-1283Apr 22, 2005
    risk 0.00cvss epss 0.02

    Multiple directory traversal vulnerabilities in Argosoft Mail Server Pro 1.8.7.6 allow remote authenticated users to (1) read arbitrary files via the UIDL parameter to the msg script or (2) copy or move the user's .eml file to arbitrary locations via the delete script, a…

  • CVE-2005-1285Apr 22, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the hilight parameter.

  • CVE-2005-1227Apr 20, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in PHProjekt 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the chatroom text submission form.

  • CVE-2005-1233Apr 20, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in index.php in PHP Labs proFile allows remote attackers to inject arbitrary web script or HTML via the (1) dir or (2) file parameters.

  • CVE-2005-1240Apr 20, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the third party tool from Castlehill, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

  • CVE-2005-1241Apr 20, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

  • CVE-2005-1244Apr 20, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in the third party tool from NetIQ, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. NOTE: the vendor has disputed this…

  • CVE-2004-1341Apr 19, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in info2www before 1.2.2.9 allows remote attackers to inject arbitrary web script or HTML via the arguments to info2www.

  • CVE-2005-0755Apr 19, 2005
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in RealPlayer 10 and earlier, Helix Player before 10.0.4, and RealOne Player v1 and v2 allows remote attackers to execute arbitrary code via a long hostname in a RAM file.

  • CVE-2005-0752Apr 18, 2005
    risk 0.00cvss epss 0.04

    The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.

  • CVE-2005-0753Apr 18, 2005
    risk 0.00cvss epss 0.05

    Buffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.

  • CVE-2005-1107Apr 18, 2005
    risk 0.00cvss epss 0.00

    McAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain privileges or disable protection by modifying certain files.

  • CVE-2005-1138Apr 18, 2005
    risk 0.00cvss epss 0.01

    Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain e-mail messages.

  • CVE-2005-1126Apr 15, 2005
    risk 0.00cvss epss 0.00

    The SIOCGIFCONF ioctl (ifconf function) in FreeBSD 4.x through 4.11 and 5.x through 5.4 does not properly clear a buffer before using it, which allows local users to obtain portions of sensitive kernel memory.

  • CVE-2005-1140Apr 15, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.

  • CVE-2005-1141CriApr 15, 2005
    risk 0.64cvss 9.8epss 0.03

    Integer overflow in the readpgm function in pnm.c for GOCR 0.40, when using the netpbm library, allows remote attackers to execute arbitrary code via a PNM file with large width and height values, which leads to a heap-based buffer overflow.

  • CVE-2005-1142Apr 15, 2005
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values.

  • CVE-2005-1308Apr 15, 2005
    risk 0.03cvss epss 0.02

    SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.

  • CVE-2004-0812Apr 14, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the Linux kernel before 2.4.23, on the AMD AMD64 and Intel EM64T architectures, associated with "setting up TSS limits," allows local users to cause a denial of service (crash) and possibly execute arbitrary code.

  • CVE-2004-1004Apr 14, 2005
    risk 0.00cvss epss 0.02

    Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.

  • CVE-2004-1005Apr 14, 2005
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.

  • CVE-2004-1009Apr 14, 2005
    risk 0.00cvss epss 0.03

    Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

  • CVE-2004-1090Apr 14, 2005
    risk 0.00cvss epss 0.02

    Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."

  • CVE-2004-1091Apr 14, 2005
    risk 0.00cvss epss 0.02

    Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.