Latest CVE Feed
-
4.3
MEDIUMCVE-2005-4840
The Outlook Express Address Book control, when using Internet Explorer 6, allows remote attackers to cause a denial of service (NULL dereference and browser crash) by creating the OutlookExpress.AddressBook COM object, which is not intended for use within... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
9.4
HIGHCVE-2005-4853
The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does not restrict edit permissions to a posting's owner, which allows remote authenticated users to edit arbitrar... Read more
Affected Products : ez_publish- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-4866
Stack-based buffer overflow in JDBC Applet Server in IBM DB2 8.1 allows remote attackers to execute arbitrary by connecting and sending a long username, then disconnecting gracefully and reconnecting and sending a short username and an unexpected db2java.... Read more
Affected Products : db2_universal_database- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4838
Multiple cross-site scripting (XSS) vulnerabilities in the example web applications for Jakarta Tomcat 5.5.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) el/functions.jsp, (2) el/implicit-objects.jsp, and (3) jspx/text... Read more
Affected Products : tomcat- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4816
Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.... Read more
Affected Products : proftpd- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4827
Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, ... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4820
SMC Wireless Router model SMC7904WBRA allows remote attackers to cause a denial of service (reboot) by flooding the router with traffic.... Read more
Affected Products : smc7904wbra- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4812
The SISCO OSI stack for Windows, as used by MMS-EASE 7.10 and earlier, AX-S4 MMS 5.01 and earlier, AX-S4 ICCP 3.0103 and earlier, and the ICCP Toolkit for MMS-EASE 4.10 and earlier, allows remote attackers to cause a denial of service (process crash) via ... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2005-4808
Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4789
resmgr in SUSE Linux 9.2 and 9.3, and possibly other distributions, does not properly enforce class-specific exclude rules in some situations, which allows local users to bypass intended access restrictions for USB devices that set their class ID at the i... Read more
Affected Products : suse_linux- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4804
Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar files via unknown vectors related to deployed web applications.... Read more
Affected Products : java_system_application_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-4802
Flexbackup 1.2.1 and earlier allows local users to overwrite files and execute code via a symlink attack on temporary files. NOTE: the raw source referenced an incorrect candidate number; this is the correct number to use.... Read more
Affected Products : flexbackup- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.1
HIGHCVE-2005-4842
The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.... Read more
Affected Products : internet_explorer- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2005-4782
NetBSD 2.0 before 2.0.4, 2.1 before 2.1.1, and 3, when the kernel is compiled with "options DIAGNOSTIC," allows local users to cause a denial of service (kernel assertion panic) via a negative linger time in the SO_LINGER socket option.... Read more
Affected Products : netbsd- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-4795
Unspecified vulnerability in the multi-language environment library (libmle) in Solaris 7 and 8, as shipped with the Japanese locale, allows local users to gain privileges via unknown attack vectors.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4783
kernfs_xread in kernfs_vnops.c in NetBSD before 20050831 does not check for a negative offset when reading the message buffer, which allows local users to read arbitrary kernel memory.... Read more
Affected Products : netbsd- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2005-4777
Tashcom ASPEdit 2.9 stores the administration password (aka the FTP password) in cleartext in the registry, which might allow local users to view the password.... Read more
Affected Products : aspedit- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4839
PureTLS before 0.9b5 does not clear optional Extensions and Algorithm.Parameters values before parsing, which might trigger an information leak of values from earlier certificates.... Read more
Affected Products : puretls- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4769
SQL injection vulnerability in addrbook.php in Belchior Foundry vCard PRO 3.1 allows remote attackers to execute arbitrary SQL commands via the addr_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from t... Read more
Affected Products : vcard_pro- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-4772
liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exp... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025