Latest CVE Feed
-
7.5
HIGHCVE-2005-4818
Multiple SQL injection vulnerabilities in Copernicus Europa allow remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.... Read more
Affected Products : europa- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-4786
Buffer overflow in the archive decompression library (vrAZMain.dll 5.8.22.137), as used in HAURI anti-virus products including (1) ViRobot Expert 4.0, (2) ViRobot Advanced Server, and (3) HAURI LiveCall, allows user-assisted attackers to execute arbitrary... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4756
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP5 and earlier, do not properly validate derived Principals with multiple PrincipalValidators, which might allow attackers to gain privileges.... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-4739
IBM DB2 Universal Database (UDB) 820 before version 8 FixPak 10 (s050811) allows remote authenticated users to cause a denial of service (application crash) by using a table function for an instance of snapshot_tbreorg, which triggers a trap in sqlnr_ESto... Read more
Affected Products : db2_universal_database- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-4648
Buffer overflow in Illustrate dBpowerAMP Music Converter 11.5 and earlier, possibly including (1) MusicConverter.exe, (2) playlist.exe, and (3) amp.exe, allows user-assisted attackers to cause a denial of service or execute arbitrary code via a .m3u playl... Read more
Affected Products : dbpoweramp_music_converter- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4647
Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL commands via the (1) forumsId and (2) topicId parameters in index.php. NOTE: the provenance of this information is unknown; the details ... Read more
Affected Products : pearl_forums- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4611
SQL injection vulnerability in search.php in Free ClickBank 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keywords parameter.... Read more
Affected Products : free_clickbank- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4609
index.php in BugPort 1.147 and earlier allows remote attackers to obtain sensitive information such as full path and system configuration via an invalid action parameter.... Read more
Affected Products : bugport- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3620
The management interface for VMware ESX Server 2.0.x before 2.0.2 patch 1, 2.1.x before 2.1.3 patch 1, and 2.x before 2.5.3 patch 2 records passwords in cleartext in URLs that are stored in world-readable web server log files, which allows local users to ... Read more
Affected Products : esx- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1528
Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.... Read more
Affected Products : rtos- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4843
The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.... Read more
Affected Products : internet_explorer- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2005-4841
The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.... Read more
Affected Products : internet_explorer- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-4767
BEA WebLogic Server and WebLogic Express 8.1 SP5 and earlier, and 7.0 SP6 and earlier, when using username/password authentication, does not lock out a username after the maximum number of invalid login attempts, which makes it easier for remote attackers... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4720
Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large value of the WIDTH attribute, which triggers a problem related to representation of floating-point numbers, l... Read more
Affected Products : firefox- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4705
BEA WebLogic Server and WebLogic Express 8.1 through SP4, 7.0 through SP6, and 6.1 through SP7, when a Java client application creates an SSL connection to the server after it has already created an insecure connection, will use the insecure connection, w... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4640
SQL injection vulnerability in index.php in class-1 Poll Software 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) pollid or (2) previouspoll parameters.... Read more
Affected Products : poll_software- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4638
index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to obtain the full path via (1) _a and (2) newsid parameters in the news module, (3) downloaditemid parameter in the downloads module, and (4) kbarticleid parameter in the knowled... Read more
Affected Products : supportsuite- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4726
MUTE 0.4 uses improper flood protection algorithms, which allows remote attackers to obtain sensitive information (privacy leak and search result data) by controlling a drop chain neighbor that is near the end of a message chain.... Read more
Affected Products : mute- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-4819
Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : lotus_domino- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4788
resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, allows local users to bypass access control rules for USB devices via "alternate syntax for specifying USB devices."... Read more
Affected Products : suse_linux- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025