Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2005-4266

    WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the... Read more

    Affected Products : mdaemon worldclient
    • Published: Dec. 15, 2005
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2005-4257

    Linksys WRT54GS and BEFW11S4 allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND). NOTE: the provenance of this issue is unknown; the ... Read more

    Affected Products : befw11s4 befw11s4_v3 befw11s4_v4 wrt54gs
    • Published: Dec. 15, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-4260

    Interpretation conflict in includes/mainfile.php in PHP-Nuke 7.9 and later allows remote attackers to perform cross-site scripting (XSS) attacks by replacing the ">" in the tag with a "<", which bypasses the regular expressions that sanitize the data, but... Read more

    Affected Products : php-nuke
    • Published: Dec. 15, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-4249

    ADP Forum 2.0 through 2.0.3 stores sensitive information in plaintext files under the web document root with insufficient access control, which allows remote attackers to obtain user credentials via requests to the forum/users directory.... Read more

    Affected Products : adp_forum
    • Published: Dec. 15, 2005
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2005-4258

    Unspecified Cisco Catalyst Switches allow remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LanD). NOTE: the provenance of this issue is unknown... Read more

    • Published: Dec. 15, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-4253

    Cross-site scripting (XSS) vulnerability in getdox.php in Torrential 1.2 allows remote attackers to inject arbitrary web script or HTML via the URL. NOTE: this might be resultant from CVE-2005-4160.... Read more

    Affected Products : torrential
    • Published: Dec. 15, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4259

    Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of... Read more

    Affected Products : aspbb
    • Published: Dec. 15, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-4256

    Cross-site scripting (XSS) vulnerability in forum.asp in ASP-DEV XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via the forum_title parameter. NOTE: the provenance of this issue is unknown; the details are obtained solely fro... Read more

    Affected Products : xm_forum
    • Published: Dec. 15, 2005
    • Modified: Apr. 03, 2025
  • 7.8

    HIGH
    CVE-2005-1928

    Trend Micro ServerProtect EarthAgent for Windows Management Console 5.58 and possibly earlier versions, when running with Trend Micro Control Manager 2.5 and 3.0, and Damage Cleanup Server 1.1, allows remote attackers to cause a denial of service (CPU con... Read more

    Affected Products : serverprotect_earthagent
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1929

    Multiple heap-based buffer overflows in (1) isaNVWRequest.dll and (2) relay.dll in Trend Micro ServerProtect Management Console 5.58 and earlier, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, allow remote attackers to execute arbit... Read more

    Affected Products : serverprotect
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2005-3360

    The installation of Trend Micro PC-Cillin Internet Security 2005 12.00 build 1244, and probably previous versions, uses insecure default ACLs, which allows local users to cause a denial of service (disabled service) and gain system privileges by modifying... Read more

    Affected Products : pc-cillin_2005
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1930

    Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Server 1.1, and possibly earlier versions, allows remote atta... Read more

    Affected Products : serverprotect
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-4242

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Turba H3 2.0.4 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the address book and (2) contact data.... Read more

    Affected Products : turba_h3
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 4.9

    MEDIUM
    CVE-2005-3358

    Linux kernel before 2.6.15 allows local users to cause a denial of service (panic) via a set_mempolicy call with a 0 bitmask, which causes a panic when a page fault occurs.... Read more

    Affected Products : linux_kernel enterprise_linux
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2005-2829

    Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display ... Read more

    Affected Products : internet_explorer ie
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2830

    Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."... Read more

    Affected Products : internet_explorer ie
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4251

    Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php.... Read more

    Affected Products : mcgallery_pro
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4227

    Multiple "potential" SQL injection vulnerabilities in DCP-Portal 6.1.1 might allow remote attackers to execute arbitrary SQL commands via (1) the password and username parameters in advertiser.php, (2) the aid parameter in announcement.php, (3) the dcp5_m... Read more

    Affected Products : dcp-portal
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4225

    Multiple "potential" SQL injection vulnerabilities in myBloggie 2.1.3 beta might allow remote attackers to execute arbitrary SQL commands via (1) the category parameter in add.php, (2) the cat_desc parameter in addcat.php, (3) the level and user parameter... Read more

    Affected Products : mybloggie
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-4226

    Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute arbitrary SQL commands via (1) the ref parameter in download.php, (2) the direction, msg, sforum, reason, subname, and toform parameters... Read more

    Affected Products : phpwebthings
    • Published: Dec. 14, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 292864 Results