Latest CVE Feed
-
7.5
HIGHCVE-2005-4270
Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.... Read more
Affected Products : appscan_qa- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4269
mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in ... Read more
- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2005-4268
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.... Read more
Affected Products : cpio- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4248
Multiple cross-site scripting (XSS) vulnerabilities in QuickPayPro 3.1 allow remote attackers to inject arbitrary web script or HTML via various fields, such as those in (1) communication/subscribers.tracking.add.php, (2) support/tickets.add.php, and (3) ... Read more
Affected Products : quickpaypro- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4262
Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE... Read more
Affected Products : envolution- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4243
Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) popupid parameter in popups.edit.php; (2) so, (3) sb, and (4) nr parameters in customer.tickets.view.php; (5) subrackingid param... Read more
Affected Products : quickpaypro- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4263
SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.... Read more
Affected Products : envolution- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4259
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of... Read more
Affected Products : aspbb- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4261
Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectors, related to "a possible security flaw caused by a bug in Perl." NOTE: unless CP+ includes its own copy of Perl ... Read more
Affected Products : cp\+- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4255
Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter.... Read more
Affected Products : wikkawiki- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4253
Cross-site scripting (XSS) vulnerability in getdox.php in Torrential 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL. NOTE: this might be resultant from CVE-2005-4160.... Read more
Affected Products : torrential- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4260
Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but... Read more
Affected Products : php-nuke- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4258
Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown... Read more
Affected Products : ios catalyst catalyst_1200_series catalyst_1900_series catalyst_2800_series catalyst_2820 catalyst_2900 catalyst_2901 catalyst_2902 catalyst_2920 +61 more products- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4257
Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND). NOTE: the provenance of this issue is unknown; the ... Read more
- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4266
WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the... Read more
- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4254
SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : dream_poll- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4249
ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via requests to the forum/users directory.... Read more
Affected Products : adp_forum- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4264
Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parameter.... Read more
Affected Products : php_support_tickets- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4256
Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of this issue is unknown; the details are obtained solely fro... Read more
Affected Products : xm_forum- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-1928
Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU con... Read more
Affected Products : serverprotect_earthagent- Published: Dec. 14, 2005
- Modified: Apr. 03, 2025