Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2005-3042

    miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).... Read more

    Affected Products : webmin usermin
    • EPSS Score: %2.20
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3035

    Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110.... Read more

    Affected Products : driverstudio
    • EPSS Score: %0.92
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3032

    Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument.... Read more

    Affected Products : vxtftpsrv
    • EPSS Score: %2.92
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3039

    SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter.... Read more

    Affected Products : mall23
    • EPSS Score: %0.58
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3038

    Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."... Read more

    Affected Products : hosting_controller
    • EPSS Score: %0.39
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-3036

    File Transfer Anywhere 3.01 stores sensitive password information in plaintext in the PASS value in the "File Transfer Anywhere" registry key, which allows local users to gain privileges.... Read more

    Affected Products : file_transfer_anywhere
    • EPSS Score: %0.06
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3034

    Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session.... Read more

    Affected Products : driverstudio
    • EPSS Score: %0.56
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3033

    Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.... Read more

    Affected Products : vxweb
    • EPSS Score: %2.02
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3043

    SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter.... Read more

    Affected Products : mall23
    • EPSS Score: %1.32
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3031

    Buffer overflow in vxFtpSrv 0.9.7 allows remote attackers to execute arbitrary code via a long USER name.... Read more

    Affected Products : vxftpsrv
    • EPSS Score: %4.76
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3040

    Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter.... Read more

    Affected Products : vista
    • EPSS Score: %0.76
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-3037

    Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL.... Read more

    Affected Products : handy_address_book_server
    • EPSS Score: %0.44
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3041

    Unspecified "drag-and-drop vulnerability" in Opera Web Browser before 8.50 on Windows allows "unintentional file uploads."... Read more

    Affected Products : opera_browser
    • EPSS Score: %0.44
    • Published: Sep. 22, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3018

    Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.... Read more

    Affected Products : safari
    • EPSS Score: %4.45
    • Published: Sep. 21, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3026

    Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter.... Read more

    Affected Products : epay
    • EPSS Score: %4.21
    • Published: Sep. 21, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3022

    Multiple SQL injection vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) announcement parameter to announcement.php, (2) userid parameter to user.php, (3) calendar parameter to admincalenda... Read more

    Affected Products : vbulletin
    • EPSS Score: %0.52
    • Published: Sep. 21, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3029

    Stack-based buffer overflow in AhnLab V3Pro 2004 build 6.0.0.383, V3 VirusBlock 2005 build 6.0.0.383, and V3Net for Windows Server 6.0 build 6.0.0.383 allows remote attackers to execute arbitrary code via a long filname in an ACE archive.... Read more

    Affected Products : v3_virusblock_2005 v3net v3pro_2004
    • EPSS Score: %4.64
    • Published: Sep. 21, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-3021

    image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action.... Read more

    Affected Products : vbulletin
    • EPSS Score: %0.20
    • Published: Sep. 21, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-3023

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via certain arguments to (1) announcement.php, (2) admincalendar.php, (3) bbcode.php, (4) cronadmin.php, (5) e... Read more

    Affected Products : vbulletin
    • EPSS Score: %0.35
    • Published: Sep. 21, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3027

    Sybari Antigen 8.0 SR2 does not properly filter SMTP messages, which allows remote attackers to bypass custom filter rules and send file attachments of arbitrary file types via a message with a subject of "Antigen forwarded attachment".... Read more

    Affected Products : antigen
    • EPSS Score: %1.27
    • Published: Sep. 21, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 291890 Results