VYPR

CVEs

378,473 total · page 7357 of 7,570

  • CVE-2005-0115Jan 24, 2005
    risk 0.00cvss epss 0.03

    Stack-based buffer overflow in DataRescue Interactive Disassembler (IDA) Pro 4.7 allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.

  • CVE-2005-0145Jan 24, 2005
    risk 0.00cvss epss 0.01

    Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

  • CVE-2005-0308Jan 24, 2005
    risk 0.08cvss epss 0.66

    Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import or export function name.

  • CVE-2005-0193Jan 22, 2005
    risk 0.03cvss epss 0.01

    Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.

  • CVE-2005-0566Jan 22, 2005
    risk 0.04cvss epss 0.16

    Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.

  • CVE-2004-1057Jan 21, 2005
    risk 0.00cvss epss 0.00

    Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages.

  • CVE-2004-1184Jan 21, 2005
    risk 0.00cvss epss 0.01

    The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.

  • CVE-2004-1185Jan 21, 2005
    risk 0.00cvss epss 0.04

    Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.

  • CVE-2005-0300Jan 20, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter.

  • CVE-2005-1846Jan 20, 2005
    risk 0.00cvss epss 0.01

    Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.

  • CVE-2005-1847Jan 20, 2005
    risk 0.00cvss epss 0.02

    Multiple buffer overflows in YaMT before 0.5_2 allow attackers to execute arbitrary code via the (1) rename or (2) sort options.

  • CVE-2005-0186Jan 19, 2005
    risk 0.00cvss epss 0.03

    Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet to the SCCP port.

  • CVE-2005-0191Jan 19, 2005
    risk 0.00cvss epss 0.03

    Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.

  • CVE-2005-0116Jan 18, 2005
    risk 0.09cvss epss 0.75

    AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.

  • CVE-2005-0297Jan 18, 2005
    risk 0.00cvss epss 0.02

    SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.

  • CVE-2005-0221Jan 17, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.

  • CVE-2005-0290Jan 17, 2005
    risk 0.00cvss epss 0.02

    NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.

  • CVE-2005-0291Jan 17, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.

  • CVE-2005-0292Jan 17, 2005
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in index.php in PHP Gift Registry (phpGiftReg) 1.4.0, and possibly other versions before 1.5.0b1, allow remote attackers to execute arbitrary SQL commands via the (1) messageid, (2) shopper, (3) shopfor, or (4) itemid parameters.

  • CVE-2005-0295Jan 17, 2005
    risk 0.00cvss epss 0.00

    npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.

  • CVE-2005-0296Jan 17, 2005
    risk 0.00cvss epss 0.03

    NOTE: this issue has been disputed by the vendor. The error module in Novell GroupWise WebAccess allows remote attackers who have not authenticated to read potentially sensitive information, such as the version, via an incorrect login and a modified (1) error or (2) modify…

  • CVE-2005-0294Jan 16, 2005
    risk 0.00cvss epss 0.02

    minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.

  • CVE-2005-0094Jan 15, 2005
    risk 0.01cvss epss 0.09

    Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.

  • CVE-2005-0095Jan 15, 2005
    risk 0.06cvss epss 0.69

    The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.

  • CVE-2005-0110Jan 14, 2005
    risk 0.01cvss epss 0.07

    Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated using the createElement…

  • CVE-2005-0113Jan 14, 2005
    risk 0.00cvss epss 0.00

    inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.

  • CVE-2005-0069Jan 13, 2005
    risk 0.00cvss epss 0.00

    The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.

  • CVE-2005-0111Jan 13, 2005
    risk 0.00cvss epss 0.04

    Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.

  • CVE-2005-0381Jan 13, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.

  • CVE-2005-0740Jan 13, 2005
    risk 0.00cvss epss 0.02

    The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.

  • CVE-2005-0376Jan 12, 2005
    risk 0.00cvss epss 0.02

    PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.

  • CVE-2005-0456Jan 12, 2005
    risk 0.00cvss epss 0.03

    Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.

  • CVE-2004-0897Jan 11, 2005
    risk 0.03cvss epss 0.43

    The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

  • CVE-2004-0991Jan 11, 2005
    risk 0.00cvss epss 0.04

    Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.

  • CVE-2004-1039Jan 11, 2005
    risk 0.00cvss epss 0.02

    The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a separate process for each…

  • CVE-2005-0097Jan 11, 2005
    risk 0.01cvss epss 0.11

    The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.

  • CVE-2005-0108Jan 11, 2005
    risk 0.00cvss epss 0.03

    Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.

  • CVE-2005-0117Jan 11, 2005
    risk 0.00cvss epss 0.00

    Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.

  • CVE-2005-0288Jan 11, 2005
    risk 0.00cvss epss 0.01

    The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.

  • CVE-2004-0139Jan 10, 2005
    risk 0.00cvss epss 0.02

    Unknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_bind's behavior," has unknown impact and attack vectors.

  • CVE-2004-0568Jan 10, 2005
    risk 0.03cvss epss 0.35

    HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file…

  • CVE-2004-0571Jan 10, 2005
    risk 0.02cvss epss 0.31

    Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability…

  • CVE-2004-0770Jan 10, 2005
    risk 0.00cvss epss 0.00

    romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.

  • CVE-2004-0883Jan 10, 2005
    risk 0.00cvss epss 0.04

    Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read…

  • CVE-2004-0893Jan 10, 2005
    risk 0.00cvss epss 0.02

    The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel…

  • CVE-2004-0894Jan 10, 2005
    risk 0.03cvss epss 0.03

    LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.

  • CVE-2004-0899Jan 10, 2005
    risk 0.06cvss epss 0.73

    The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP…

  • CVE-2004-0900Jan 10, 2005
    risk 0.02cvss epss 0.26

    The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."

  • CVE-2004-0901Jan 10, 2005
    risk 0.03cvss epss 0.32

    Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion…

  • CVE-2004-0914Jan 10, 2005
    risk 0.01cvss epss 0.09

    Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could…