Latest CVE Feed
-
6.4
MEDIUMCVE-2005-4684
Konqueror can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of the hostname en... Read more
Affected Products : konqueror- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2005-4733
NetBSD 2.0 before 20050316 and NetBSD-current before 20050112 allow local users to cause a denial of service (infinite loop and system hang) by calling the F_CLOSEM fcntl with a parameter value of 0.... Read more
Affected Products : netbsd- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4704
Unspecified vulnerability in BEA WebLogic Server and WebLogic Express 8.1 through SP3, 7.0 through SP6, and 6.1 through SP7, when SSL is intended to be used, causes an unencrypted protocol to be used in certain unspecified circumstances, which causes user... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4824
PHP remote file inclusion vulnerability in web/classes.php in Siteframe before 3.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the LOCAL_PATH parameter, a different vulnerability than CVE-2005-1965.... Read more
Affected Products : siteframe- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-4702
SQL injection vulnerability in the favorites module in index.php in IPBProArcade 2.5.2 allows remote attackers to inject arbitrary SQL commands via the gameid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely... Read more
Affected Products : ipbproarcade- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-4748
PHP remote file include vulnerability in functions_admin.php in Virtual War (VWar) 1.5.0 R10 allows remote attackers to include and execute arbitrary PHP code via unspecified attack vectors. NOTE: this issue has been referred to as XSS, but it is clear f... Read more
Affected Products : virtual_war- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-4758
Unspecified vulnerability in the Administration server in BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier allows remote authenticated Admin users to read arbitrary files via unknown attack vectors related to an "internal servlet" accessed thr... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4757
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier, and 7.0 SP5 and earlier, do not properly "constrain" a "/" (slash) servlet root URL pattern, which might allow remote attackers to bypass intended servlet protections.... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2005-4765
BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier and 7.0 SP6 and earlier, when using the weblogic.Deployer command with the t3 protocol, does not use the secure t3s protocol even when an Administration port is enabled on the Administration ser... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-4771
Trusted Mobility Agent PC Policy in Trust Digital Trusted Mobility Suite provides a cancel button that bypasses the domain-authentication prompt, which allows local users to sync a handheld (PDA) device despite a policy setting that sync is unauthorized.... Read more
Affected Products : trusted_mobility_suite- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-4779
verifiedexecioctl in verified_exec.c in NetBSD 2.0.2 calls NDINIT with UIO_USERSPACE rather than UID_SYSSPACE, which removes the functionality of the verified exec kernel subsystem and might allow local users to execute Trojan horse programs.... Read more
Affected Products : netbsd- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4780
Cross-site scripting (XSS) vulnerability in Fidra Lighthouse CMS 1.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the search parameter in a query_string to the home page. NOTE: The vendor disputes this issue, saying "Li... Read more
Affected Products : lighthouse_cms- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2005-4773
The configuration of VMware ESX Server 2.x, 2.0.x, 2.1.x, and 2.5.x allows local users to cause a denial of service (shutdown) via the (1) halt, (2) poweroff, and (3) reboot scripts executed at the service console.... Read more
Affected Products : esx- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4785
Cross-site scripting (XSS) vulnerability in QuickBlogger 1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) author ("your name") and (2) "comment" section.... Read more
Affected Products : quickblogger- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.6
MEDIUMCVE-2005-4784
Multiple buffer overflows in the POSIX readdir_r function, as used in multiple packages, allow local users to cause a denial of service and possibly execute arbitrary code via (1) a symlink attack that exploits a race condition between opendir and pathcon... Read more
Affected Products : posix- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4781
Multiple SQL injection vulnerabilities in SergiDs Top Music module 3.0 PR3 and earlier for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the (1) idartist, (2) idsong, and (3) idalbum parameters to modules.php.... Read more
Affected Products : top_music_module- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4778
The powersave daemon in SUSE Linux 10.0 before 20051007 has an unspecified "configuration problem," which allows local users to suspend the computer and possibly perform certain other unauthorized actions.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4793
Multiple unspecified vulnerabilities in the web utility function in Hitachi Cm2/Network Node Manager and JP1/Cm2/Network Node Manager before 20050930 allow attackers to execute arbitrary commands, disable services, and "exploit vulnerabilities."... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4849
Apache Derby before 10.1.2.1 exposes the (1) user and (2) password attributes in cleartext via (a) the RDBNAM parameter of the ACCSEC command and (b) the output of the DatabaseMetaData.getURL function, which allows context-dependent attackers to obtain se... Read more
Affected Products : derby- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4801
Multiple cross-site request forgery (CSRF) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to perform unauthorized actions as a logged-in user, as demonstrated by tricking the administrator to access a web... Read more
Affected Products : yapig- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025