VYPR

CVEs

378,486 total · page 7354 of 7,570

  • CVE-2005-0622Mar 1, 2005
    risk 0.00cvss epss 0.02

    RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.

  • CVE-2005-0623Mar 1, 2005
    risk 0.00cvss epss 0.03

    Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.

  • CVE-2005-0628Mar 1, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message.

  • CVE-2005-0629Mar 1, 2005
    risk 0.03cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) user or (2) Avatar parameters.

  • CVE-2005-0630Mar 1, 2005
    risk 0.00cvss epss 0.02

    sendpm.php in PBLang 4.63 allows remote authenticated users to read arbitrary files via a full pathname in the orig parameter.

  • CVE-2005-0631Mar 1, 2005
    risk 0.00cvss epss 0.01

    delpm.php in PBLang 4.63 allows remote authenticated users to delete arbitrary PM files by modifying the "id" and "a" parameters.

  • CVE-2005-0632Mar 1, 2005
    risk 0.03cvss epss 0.03

    PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.

  • CVE-2004-0945Feb 28, 2005
    risk 0.00cvss epss 0.02

    The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum.

  • CVE-2005-0603Feb 28, 2005
    risk 0.00cvss epss 0.04

    viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message.

  • CVE-2005-0608Feb 28, 2005
    risk 0.00cvss epss 0.03

    Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.

  • CVE-2005-0613Feb 28, 2005
    risk 0.03cvss epss 0.05

    Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.

  • CVE-2005-0616Feb 28, 2005
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in the Download module for PostNuke 0.750 and 0.760-RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) Program name, (2) File link, (3) Author name (4) Author e-mail address, (5) File size, (6)…

  • CVE-2005-0619Feb 28, 2005
    risk 0.03cvss epss 0.01

    Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain privileges.

  • CVE-2005-0624Feb 28, 2005
    risk 0.00cvss epss 0.00

    reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.

  • CVE-2005-0625Feb 28, 2005
    risk 0.00cvss epss 0.00

    reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.

  • CVE-2005-0107Feb 25, 2005
    risk 0.00cvss epss 0.02

    bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.

  • CVE-2005-0579Feb 25, 2005
    risk 0.00cvss epss 0.00

    nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.

  • CVE-2005-0580Feb 25, 2005
    risk 0.00cvss epss 0.00

    cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.

  • CVE-2005-0543Feb 24, 2005
    risk 0.03cvss epss 0.04

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in…

  • CVE-2005-0547Feb 24, 2005
    risk 0.00cvss epss 0.01

    Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."

  • CVE-2005-0598Feb 24, 2005
    risk 0.00cvss epss 0.03

    The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.

  • CVE-2005-0600Feb 24, 2005
    risk 0.00cvss epss 0.02

    Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.

  • CVE-2004-0481Feb 23, 2005
    risk 0.00cvss epss 0.00

    The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.

  • CVE-2005-0516Feb 23, 2005
    risk 0.00cvss epss 0.02

    The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.

  • CVE-2005-0517Feb 23, 2005
    risk 0.03cvss epss 0.01

    PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.

  • CVE-2005-0518Feb 23, 2005
    risk 0.03cvss epss 0.01

    eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.

  • CVE-2005-0520Feb 23, 2005
    risk 0.00cvss epss 0.04

    ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.

  • CVE-2005-0521Feb 23, 2005
    risk 0.03cvss epss 0.01

    SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.

  • CVE-2005-0160Feb 22, 2005
    risk 0.00cvss epss 0.03

    Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.

  • CVE-2005-0161Feb 22, 2005
    risk 0.03cvss epss 0.01

    Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.

  • CVE-2005-0514Feb 22, 2005
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.

  • CVE-2005-0535Feb 22, 2005
    risk 0.00cvss epss 0.02

    Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.

  • CVE-2005-0937Feb 22, 2005
    risk 0.00cvss epss 0.00

    Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executing mmap or other…

  • CVE-2005-0467Feb 21, 2005
    risk 0.00cvss epss 0.04

    Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after…

  • CVE-2005-0494Feb 21, 2005
    risk 0.03cvss epss 0.03

    The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.

  • CVE-2005-0496CriFeb 21, 2005
    risk 0.64cvss 9.8epss 0.03

    Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.

  • CVE-2005-0503Feb 21, 2005
    risk 0.00cvss epss 0.00

    uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.

  • CVE-2005-0511Feb 21, 2005
    risk 0.06cvss epss 0.36

    misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.

  • CVE-2005-0512Feb 21, 2005
    risk 0.00cvss epss 0.01

    PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than…

  • CVE-2005-0537Feb 21, 2005
    risk 0.00cvss epss 0.01

    Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.

  • CVE-2005-0499Feb 20, 2005
    risk 0.00cvss epss 0.01

    Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.

  • CVE-2005-0092Feb 19, 2005
    risk 0.00cvss epss 0.00

    Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).

  • CVE-2005-0495Feb 19, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.

  • CVE-2005-0513Feb 19, 2005
    risk 0.04cvss epss 0.06

    PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autocheck.php and modifying…

  • CVE-2005-0242Feb 18, 2005
    risk 0.00cvss epss 0.00

    The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions.

  • CVE-2005-0502Feb 18, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.

  • CVE-2005-0519Feb 18, 2005
    risk 0.00cvss epss 0.04

    ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability than CVE-2005-0520.

  • CVE-2005-0243Feb 17, 2005
    risk 0.00cvss epss 0.01

    Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing a large number of spaces…

  • CVE-2005-0462Feb 17, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.

  • CVE-2005-0105Feb 16, 2005
    risk 0.03cvss epss 0.01

    Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.