VYPR

CVEs

378,488 total · page 7352 of 7,570

  • CVE-2005-0470Mar 14, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.

  • CVE-2005-0471Mar 14, 2005
    risk 0.00cvss epss 0.03

    Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in…

  • CVE-2005-0472Mar 14, 2005
    risk 0.00cvss epss 0.05

    Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.

  • CVE-2005-0473Mar 14, 2005
    risk 0.00cvss epss 0.03

    The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.

  • CVE-2005-0504Mar 14, 2005
    risk 0.00cvss epss 0.01

    Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value.

  • CVE-2005-0505Mar 14, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in Information Resource Manager (IRM) before 1.5.2.1 allows remote attackers to have "potentially serious" impact, related to LDAP logins.

  • CVE-2005-0506Mar 14, 2005
    risk 0.03cvss epss 0.03

    The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key, which allows local and possibly remote users to steal usernames and passwords and impersonate other users via keys such as Avaya\IP400\Generic.

  • CVE-2005-0507Mar 14, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in SD Server 4.0.70 and earlier allows remote attackers to read arbitrary files via .. sequences in an HTTP request.

  • CVE-2005-0508Mar 14, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."

  • CVE-2005-0509Mar 14, 2005
    risk 0.01cvss epss 0.16

    Multiple cross-site scripting (XSS) vulnerabilities in the Mono 1.0.5 implementation of ASP.NET (.Net) allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters,…

  • CVE-2005-0510Mar 14, 2005
    risk 0.00cvss epss 0.00

    The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.

  • CVE-2005-0786Mar 14, 2005
    risk 0.03cvss epss 0.02

    SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to guestbook.php.

  • CVE-2005-0788Mar 14, 2005
    risk 0.04cvss epss 0.07

    LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.

  • CVE-2005-0789Mar 14, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.

  • CVE-2005-0790Mar 14, 2005
    risk 0.00cvss epss 0.01

    phpAdsNew 2.0.4 allows remote attackers to obtain sensitive information via a direct request to (1) lib-xmlrpcs.inc.php, (2) maintenance-activation.php, (3) maintenance-cleantables.php, (4) maintenance-autotargeting.php, (5) maintenance-reports.php, (6) phpads.php, (7)…

  • CVE-2005-0791Mar 14, 2005
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the refresh parameter.

  • CVE-2005-0795Mar 14, 2005
    risk 0.03cvss epss 0.02

    HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via a modified vote_filename parameter.

  • CVE-2005-0765Mar 12, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the JXTA dissector in Ethereal 0.10.9 allows remote attackers to cause a denial of service (application crash).

  • CVE-2005-0780Mar 12, 2005
    risk 0.03cvss epss 0.05

    paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3) category.php, (4) file.php, (5) team.php, (6) license.php, (7) custom.php, (8) admins.php, or (9) backupdb.php, which reveal the path in a…

  • CVE-2005-0731Mar 10, 2005
    risk 0.04cvss epss 0.07

    PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to Filelist.html.

  • CVE-2005-0748Mar 10, 2005
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in initdb.php for WEBInsta Mailing list manager 1.3d allows remote attackers to execute arbitrary PHP code by modifying the absolute_path parameter to reference a URL on a remote web server that contains the code.

  • CVE-2005-0774Mar 10, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in member.php and possibly other scripts in PhotoPost PHP 5.0 RC3 allows remote attackers to execute arbitrary SQL commands via the uid parameter.

  • CVE-2005-0719Mar 9, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the systems message queue in HP Tru64 Unix 4.0F PK8 through 5.1B-2/PK4 allows local users to cause a denial of service (process crash) for processes such as nfsstat, pfstat, arp, ogated, rarpd, route, sendmail, srconfig, strsetup, trpt, netstat, and…

  • CVE-2005-0736Mar 9, 2005
    risk 0.03cvss epss 0.02

    Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.

  • CVE-2005-0745Mar 9, 2005
    risk 0.00cvss epss 0.00

    UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset.

  • CVE-2005-0098Mar 8, 2005
    risk 0.00cvss epss 0.01

    Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.

  • CVE-2005-0099Mar 8, 2005
    risk 0.00cvss epss 0.00

    The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.

  • CVE-2005-0626Mar 8, 2005
    risk 0.00cvss epss 0.01

    Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.

  • CVE-2005-0685Mar 8, 2005
    risk 0.00cvss epss 0.02

    Multiple access validation errors in OutStart Participate Enterprise (PE) allow remote attackers to (1) browse arbitrary directory trees by modifying the rootFolder parameter to displaynavigator.jsp, (2) rename arbitrary directory objects by modifying the selectedObject…

  • CVE-2005-0696Mar 8, 2005
    risk 0.00cvss epss 0.05

    Buffer overflow in ArGoSoft FTP Server 1.4.2.8 allows remote authenticated users to execute arbitrary code via a long DELE command. NOTE: this issue was later reported to also affect 1.4.3.5.

  • CVE-2005-0699Mar 8, 2005
    risk 0.01cvss epss 0.06

    Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.

  • CVE-2005-0720Mar 8, 2005
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by modifying the skinfile parameter to reference a URL on a remote web server that contains the code.

  • CVE-2005-0723Mar 8, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the jumpmenu function in functions.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL parameters, which is not properly cleansed in the $pageurl variable, as demonstrated using…

  • CVE-2005-0725Mar 8, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to execute arbitrary SQL commands via the articleid parameter to article.php.

  • CVE-2005-0741Mar 8, 2005
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.

  • CVE-2005-0747Mar 8, 2005
    risk 0.00cvss epss 0.01

    ApplyYourself i-Class allows remote attackers to obtain sensitive information about their own applications by reusing the hidden ID field, as demonstrated using the id parameter to ApplicantDecision.asp.

  • CVE-2005-0177Mar 7, 2005
    risk 0.00cvss epss 0.02

    nls_ascii.c in Linux before 2.6.8.1 uses an incorrect table size, which allows attackers to cause a denial of service (kernel crash) via a buffer overflow.

  • CVE-2005-0178Mar 7, 2005
    risk 0.00cvss epss 0.00

    Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.

  • CVE-2005-0179Mar 7, 2005
    risk 0.00cvss epss 0.00

    Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.

  • CVE-2005-0180Mar 7, 2005
    risk 0.00cvss epss 0.01

    Multiple integer signedness errors in the sg_scsi_ioctl function in scsi_ioctl.c for Linux 2.6.x allow local users to read or modify kernel memory via negative integers in arguments to the scsi ioctl, which bypass a maximum length check before calling the copy_from_user and…

  • CVE-2005-0548Mar 7, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.

  • CVE-2005-0667Mar 7, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.

  • CVE-2005-0680Mar 7, 2005
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.

  • CVE-2005-0686Mar 7, 2005
    risk 0.00cvss epss 0.02

    Integer overflow in mlterm 2.5.0 through 2.9.1, with gdk-pixbuf support enabled, allows remote attackers to execute arbitrary code via a large image file that is used as a background.

  • CVE-2005-0689Mar 7, 2005
    risk 0.04cvss epss 0.10

    includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.

  • CVE-2005-0690Mar 7, 2005
    risk 0.00cvss epss 0.00

    Gene6 FTP Server does not properly restrict access to the control console, which allows local users to modify the server configuration and gain privileges, as demonstrated by defining a SITE command.

  • CVE-2005-0693Mar 7, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.

  • CVE-2005-0694Mar 7, 2005
    risk 0.00cvss epss 0.02

    Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.

  • CVE-2005-0695Mar 7, 2005
    risk 0.00cvss epss 0.01

    The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field.

  • CVE-2005-0697Mar 7, 2005
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the process_picture function xp_publish.php in CopperExport 0.2.1 allows remote attackers to execute arbitrary SQL commands, possibly via the (1) title, (2) caption, or (3) keywords parameters.