| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-0622 | 0.00 | — | 0.02 | Mar 1, 2005 | RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space. | |||
| CVE-2005-0623 | 0.00 | — | 0.03 | Mar 1, 2005 | Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL. | |||
| CVE-2005-0628 | 0.00 | — | 0.01 | Mar 1, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message. | |||
| CVE-2005-0629 | — | 0.03 | — | 0.02 | Mar 1, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters. | ||
| CVE-2005-0630 | 0.00 | — | 0.02 | Mar 1, 2005 | sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter. | |||
| CVE-2005-0631 | 0.00 | — | 0.01 | Mar 1, 2005 | delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters. | |||
| CVE-2005-0632 | 0.03 | — | 0.03 | Mar 1, 2005 | PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter. | |||
| CVE-2004-0945 | 0.00 | — | 0.02 | Feb 28, 2005 | The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum. | |||
| CVE-2005-0603 | 0.00 | — | 0.04 | Feb 28, 2005 | viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message. | |||
| CVE-2005-0608 | 0.00 | — | 0.03 | Feb 28, 2005 | Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent. | |||
| CVE-2005-0613 | 0.03 | — | 0.05 | Feb 28, 2005 | Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files. | |||
| CVE-2005-0616 | 0.00 | — | 0.01 | Feb 28, 2005 | Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6)… | |||
| CVE-2005-0619 | 0.03 | — | 0.01 | Feb 28, 2005 | Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges. | |||
| CVE-2005-0624 | 0.00 | — | 0.00 | Feb 28, 2005 | reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords. | |||
| CVE-2005-0625 | 0.00 | — | 0.00 | Feb 28, 2005 | reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd. | |||
| CVE-2005-0107 | 0.00 | — | 0.02 | Feb 25, 2005 | bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands. | |||
| CVE-2005-0579 | 0.00 | — | 0.00 | Feb 25, 2005 | nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication. | |||
| CVE-2005-0580 | 0.00 | — | 0.00 | Feb 25, 2005 | cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file. | |||
| CVE-2005-0543 | 0.03 | — | 0.04 | Feb 24, 2005 | Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in… | |||
| CVE-2005-0547 | 0.00 | — | 0.01 | Feb 24, 2005 | Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files." | |||
| CVE-2005-0598 | 0.00 | — | 0.03 | Feb 24, 2005 | The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets. | |||
| CVE-2005-0600 | 0.00 | — | 0.02 | Feb 24, 2005 | Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded. | |||
| CVE-2004-0481 | 0.00 | — | 0.00 | Feb 23, 2005 | The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file. | |||
| CVE-2005-0516 | 0.00 | — | 0.02 | Feb 23, 2005 | The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails. | |||
| CVE-2005-0517 | 0.03 | — | 0.01 | Feb 23, 2005 | PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges. | |||
| CVE-2005-0518 | 0.03 | — | 0.01 | Feb 23, 2005 | eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values. | |||
| CVE-2005-0520 | 0.00 | — | 0.04 | Feb 23, 2005 | ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519. | |||
| CVE-2005-0521 | — | 0.03 | — | 0.01 | Feb 23, 2005 | SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges. | ||
| CVE-2005-0160 | 0.00 | — | 0.03 | Feb 22, 2005 | Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages. | |||
| CVE-2005-0161 | 0.03 | — | 0.01 | Feb 22, 2005 | Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames. | |||
| CVE-2005-0514 | 0.00 | — | 0.02 | Feb 22, 2005 | Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters. | |||
| CVE-2005-0535 | 0.00 | — | 0.02 | Feb 22, 2005 | Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users. | |||
| CVE-2005-0937 | 0.00 | — | 0.00 | Feb 22, 2005 | Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mmap or other… | |||
| CVE-2005-0467 | 0.00 | — | 0.04 | Feb 21, 2005 | Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after… | |||
| CVE-2005-0494 | 0.03 | — | 0.03 | Feb 21, 2005 | The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request. | |||
| CVE-2005-0496 | Cri | 0.64 | 9.8 | 0.03 | Feb 21, 2005 | Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands. | ||
| CVE-2005-0503 | 0.00 | — | 0.00 | Feb 21, 2005 | uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges. | |||
| CVE-2005-0511 | 0.06 | — | 0.36 | Feb 21, 2005 | misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter. | |||
| CVE-2005-0512 | 0.00 | — | 0.01 | Feb 21, 2005 | PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than… | |||
| CVE-2005-0537 | 0.00 | — | 0.01 | Feb 21, 2005 | Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters. | |||
| CVE-2005-0499 | 0.00 | — | 0.01 | Feb 20, 2005 | Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries. | |||
| CVE-2005-0092 | 0.00 | — | 0.00 | Feb 19, 2005 | Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash). | |||
| CVE-2005-0495 | 0.00 | — | 0.01 | Feb 19, 2005 | Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php. | |||
| CVE-2005-0513 | 0.04 | — | 0.06 | Feb 19, 2005 | PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying… | |||
| CVE-2005-0242 | 0.00 | — | 0.00 | Feb 18, 2005 | The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions. | |||
| CVE-2005-0502 | 0.00 | — | 0.02 | Feb 18, 2005 | Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request. | |||
| CVE-2005-0519 | 0.00 | — | 0.04 | Feb 18, 2005 | ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520. | |||
| CVE-2005-0243 | 0.00 | — | 0.01 | Feb 17, 2005 | Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces… | |||
| CVE-2005-0462 | 0.00 | — | 0.01 | Feb 17, 2005 | Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter. | |||
| CVE-2005-0105 | 0.03 | — | 0.01 | Feb 16, 2005 | Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges. |
- CVE-2005-0622Mar 1, 2005risk 0.00cvss —epss 0.02
RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.
- CVE-2005-0623Mar 1, 2005risk 0.00cvss —epss 0.03
Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.
- CVE-2005-0628Mar 1, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message.
- CVE-2005-0629Mar 1, 2005risk 0.03cvss —epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.
- CVE-2005-0630Mar 1, 2005risk 0.00cvss —epss 0.02
sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.
- CVE-2005-0631Mar 1, 2005risk 0.00cvss —epss 0.01
delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters.
- CVE-2005-0632Mar 1, 2005risk 0.03cvss —epss 0.03
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.
- CVE-2004-0945Feb 28, 2005risk 0.00cvss —epss 0.02
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum.
- CVE-2005-0603Feb 28, 2005risk 0.00cvss —epss 0.04
viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message.
- CVE-2005-0608Feb 28, 2005risk 0.00cvss —epss 0.03
Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.
- CVE-2005-0613Feb 28, 2005risk 0.03cvss —epss 0.05
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
- CVE-2005-0616Feb 28, 2005risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6)…
- CVE-2005-0619Feb 28, 2005risk 0.03cvss —epss 0.01
Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.
- CVE-2005-0624Feb 28, 2005risk 0.00cvss —epss 0.00
reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.
- CVE-2005-0625Feb 28, 2005risk 0.00cvss —epss 0.00
reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.
- CVE-2005-0107Feb 25, 2005risk 0.00cvss —epss 0.02
bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.
- CVE-2005-0579Feb 25, 2005risk 0.00cvss —epss 0.00
nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.
- CVE-2005-0580Feb 25, 2005risk 0.00cvss —epss 0.00
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.
- CVE-2005-0543Feb 24, 2005risk 0.03cvss —epss 0.04
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in…
- CVE-2005-0547Feb 24, 2005risk 0.00cvss —epss 0.01
Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."
- CVE-2005-0598Feb 24, 2005risk 0.00cvss —epss 0.03
The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.
- CVE-2005-0600Feb 24, 2005risk 0.00cvss —epss 0.02
Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.
- CVE-2004-0481Feb 23, 2005risk 0.00cvss —epss 0.00
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.
- CVE-2005-0516Feb 23, 2005risk 0.00cvss —epss 0.02
The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.
- CVE-2005-0517Feb 23, 2005risk 0.03cvss —epss 0.01
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.
- CVE-2005-0518Feb 23, 2005risk 0.03cvss —epss 0.01
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.
- CVE-2005-0520Feb 23, 2005risk 0.00cvss —epss 0.04
ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.
- CVE-2005-0521Feb 23, 2005risk 0.03cvss —epss 0.01
SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.
- CVE-2005-0160Feb 22, 2005risk 0.00cvss —epss 0.03
Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.
- CVE-2005-0161Feb 22, 2005risk 0.03cvss —epss 0.01
Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.
- CVE-2005-0514Feb 22, 2005risk 0.00cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.
- CVE-2005-0535Feb 22, 2005risk 0.00cvss —epss 0.02
Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.
- CVE-2005-0937Feb 22, 2005risk 0.00cvss —epss 0.00
Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mmap or other…
- CVE-2005-0467Feb 21, 2005risk 0.00cvss —epss 0.04
Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after…
- CVE-2005-0494Feb 21, 2005risk 0.03cvss —epss 0.03
The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.
- risk 0.64cvss 9.8epss 0.03
Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.
- CVE-2005-0503Feb 21, 2005risk 0.00cvss —epss 0.00
uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.
- CVE-2005-0511Feb 21, 2005risk 0.06cvss —epss 0.36
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
- CVE-2005-0512Feb 21, 2005risk 0.00cvss —epss 0.01
PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than…
- CVE-2005-0537Feb 21, 2005risk 0.00cvss —epss 0.01
Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.
- CVE-2005-0499Feb 20, 2005risk 0.00cvss —epss 0.01
Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.
- CVE-2005-0092Feb 19, 2005risk 0.00cvss —epss 0.00
Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).
- CVE-2005-0495Feb 19, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.
- CVE-2005-0513Feb 19, 2005risk 0.04cvss —epss 0.06
PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying…
- CVE-2005-0242Feb 18, 2005risk 0.00cvss —epss 0.00
The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.
- CVE-2005-0502Feb 18, 2005risk 0.00cvss —epss 0.02
Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.
- CVE-2005-0519Feb 18, 2005risk 0.00cvss —epss 0.04
ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.
- CVE-2005-0243Feb 17, 2005risk 0.00cvss —epss 0.01
Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces…
- CVE-2005-0462Feb 17, 2005risk 0.00cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.
- CVE-2005-0105Feb 16, 2005risk 0.03cvss —epss 0.01
Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.