Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3425
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2005-3424.... Read more
Affected Products : gnump3d- EPSS Score: %0.80
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3422
Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web script or HTML via the error parameter.... Read more
Affected Products : asp_fast_forum- EPSS Score: %0.58
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3416
phpBB 2.0.17 and earlier, when register_globals is enabled and the session_start function has not been called to handle a session, allows remote attackers to bypass security checks by setting the $_SESSION and $HTTP_SESSION_VARS variables to strings inste... Read more
Affected Products : phpbb- EPSS Score: %0.84
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3417
phpBB 2.0.17 and earlier, when the register_long_arrays directive is disabled, allows remote attackers to modify global variables and bypass security mechanisms because PHP does not define the associated HTTP_* variables.... Read more
Affected Products : phpbb- EPSS Score: %0.84
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3415
phpBB 2.0.17 and earlier allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GET/POST/COOKIE (GPC) variable and a GLOBALS[] variable with the same name, which causes phpBB to unset the GLOBALS[] varia... Read more
Affected Products : phpbb- EPSS Score: %1.08
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3420
usercp_register.php in phpBB 2.0.17 allows remote attackers to modify regular expressions and execute PHP code via the signature_bbcode_uid parameter, as demonstrated by injecting an "e" modifier into a preg_replace statement.... Read more
Affected Products : phpbb- EPSS Score: %2.32
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3418
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to usercp_register.php, (2) forward_page parameter to login.php, and (3) list_cat... Read more
Affected Products : phpbb- EPSS Score: %1.45
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3421
estcmd in Hyper Estraier 1.0.1 on Windows systems allows remote attackers to read unauthorized files via a crafted search request for a filename that contains Unicode characters.... Read more
Affected Products : hyper_estraier- EPSS Score: %0.48
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3419
SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode_uid parameter, which is not properly initialized.... Read more
Affected Products : phpbb- EPSS Score: %1.31
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3412
Cross-site scripting (XSS) vulnerability in Elite Forum 1.0.0.0 allows remote attackers to inject arbitrary web script or HTML via a Post Reply to a topic, in which the reply contains a javascript: URL in an <img> tag.... Read more
Affected Products : elite_forum- EPSS Score: %7.10
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3411
Cross-site scripting (XSS) vulnerability in post.asp in Snitz Forums 2000 3.4.05 allows remote attackers to inject arbitrary web script or HTML via the type parameter in a Topic method.... Read more
Affected Products : snitz_forums_2000- EPSS Score: %0.81
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3414
eyeOS 0.8.4 stores usrinfo.xml under the web document root with insufficient access control, which allows remote attackers to obtain user credentials.... Read more
Affected Products : eyeos- EPSS Score: %1.41
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3413
Cross-site scripting (XSS) vulnerability in desktop.php in eyeOS 0.8.4 allows remote attackers to inject arbitrary web script or HTML via the motd parameter.... Read more
Affected Products : eyeos- EPSS Score: %0.57
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-3387
The startup script in packages/RedHat/ntop.init in ntop before 3.2, when ntop.conf is writable by users besides root, creates temporary files insecurely, which allows remote attackers to execute arbitrary code.... Read more
Affected Products : ntop- EPSS Score: %0.42
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3398
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTT... Read more
- EPSS Score: %39.54
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3388
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."... Read more
Affected Products : php- EPSS Score: %47.26
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3313
The IRC protocol dissector in Ethereal 0.10.13 allows remote attackers to cause a denial of service (infinite loop).... Read more
Affected Products : ethereal- EPSS Score: %3.89
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2750
Software Update in Mac OS X 10.4.2, when the user marks all updates to be ignored, exits without asking the user to reset the status of the updates, which could prevent important, security-relevant updates from being installed.... Read more
Affected Products : mac_os_x_server- EPSS Score: %0.09
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2751
memberd in Mac OS X 10.4 up to 10.4.2, in certain situations, does not quickly synchronize access control checks with changes in group membership, which could allow users to access files and other resources after they have been removed from a group.... Read more
- EPSS Score: %0.09
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3399
Multiple interpretation error in CAT-QuickHeal 8.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe... Read more
Affected Products : quick_heal- EPSS Score: %0.22
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025