Latest CVE Feed
-
7.5
HIGHCVE-2005-3941
SQL injection vulnerability in blog.php in Orca Blog 1.3b and earlier allows remote attackers to execute arbitrary SQL commands via the msg parameter.... Read more
Affected Products : orca_blog- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3944
SQL injection vulnerability in survey.php in ilyav Survey System 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the SURVEY_ID parameter.... Read more
Affected Products : faq_system- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3945
The SynAttackProtect protection in Microsoft Windows 2003 before SP1 and Windows 2000 before SP4 with Update Roll-up uses a hash of predictable data, which allows remote attackers to cause a denial of service (CPU consumption) via a flood of SYN packets t... Read more
- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3942
SQL injection vulnerability in knowledgebase-control.php in Orca Knowledgebase 2.1b and earlier allows remote attackers to execute arbitrary SQL commands via the qid parameter.... Read more
Affected Products : orca_knowledgebase- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3961
export_handler.php in WebCalendar 1.0.1 allows remote attackers to overwrite WebCalendar data files via a modified id parameter.... Read more
Affected Products : webcalendar- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3934
Buffer overflow in Symantec pcAnywhere 11.0.1, 11.5.1, and all other 32-bit versions allows remote attackers to cause a denial of service (application crash) via unknown attack vectors.... Read more
Affected Products : pcanywhere- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3958
SQL injection vulnerability in index.php in Entergal MX 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idcat parameter in a showcat action and (2) the action parameter.... Read more
Affected Products : entergal_mx- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3949
Multiple SQL injection vulnerabilities in WebCalendar 1.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) startid parameter to activity_log.php, (2) startid parameter to admin_handler.php, (3) template parameter to edit_template.php... Read more
Affected Products : webcalendar- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3931
SQL injection vulnerability in default.asp in ASP-Rider 1.6 allows remote attackers to execute arbitrary SQL commands via the HTTP referer.... Read more
Affected Products : asp-rider- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3938
SQL injection vulnerability in Softbiz FAQ Script 1.1 and earler allows remote attackers to execute arbitrary SQL commands via the id parameter in (1) index.php, (2) faq_qanda.php, (3) refer_friend.php, (4) print_article.php, or (5) add_comment.php.... Read more
Affected Products : faq- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3957
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.... Read more
Affected Products : dotclear- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3701
Unspecified vulnerability in passwordserver in Mac OS X Server 10.3.9 and 10.4.3, when creating an Open Directory master server, allows local users to gain privileges via unknown attack vectors.... Read more
Affected Products : mac_os_x_server- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3705
Heap-based buffer overflow in WebKit in Mac OS X and OS X Server 10.3.9 and 10.4.3, as used in applications such as Safari, allows remote attackers to execute arbitrary code via unknown attack vectors.... Read more
- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3704
System log server in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to spoof syslog messages in log files by injecting various control characters such as newline (NL).... Read more
- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3702
Safari in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows remote attackers to cause files to be downloaded to locations outside the download directory via a long file name.... Read more
- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2757
Heap-based buffer overflow in CoreFoundation in Mac OS X and OS X Server 10.4 through 10.4.3 allows remote attackers to execute arbitrary code via unknown attack vectors involving "validation of URLs."... Read more
- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-3700
Unknown vulnerability in iodbcadmintool in the ODBC Administrator utility in Mac OS X and OS X Server 10.3.9 and 10.4.3 allows local users to execute arbitrary code via unknown attack vectors.... Read more
- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3907
Unspecified vulnerability in Java Runtime Environment in Java JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applications via unknown attack vectors involving untrust... Read more
- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3910
merchants/index.php in Post Affiliate Pro 2.0.4 and earlier, with magic_quotes_gpc disabled, allows remote attackers to include arbitrary local files via the md parameter, possibly due to a directory traversal vulnerability.... Read more
Affected Products : post_affiliate_pro- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-3927
Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypetool.php, or the lng parameter to the in admin/inc scripts (2) archbatch.php... Read more
Affected Products : guppy- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025