Latest CVE Feed
-
5.1
MEDIUMCVE-2005-3375
Multiple interpretation error in Ikarus demo version allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a sa... Read more
Affected Products : ikarus_antivirus- EPSS Score: %0.45
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3373
Multiple interpretation error in Dr.Web 4.32b allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type... Read more
Affected Products : dr.web_antivirus- EPSS Score: %0.45
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3385
SQL injection vulnerability in Techno Dreams Mailing List script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.... Read more
Affected Products : mailing_list- EPSS Score: %2.10
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3367
Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field.... Read more
Affected Products : sparkleblog- EPSS Score: %0.34
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3364
Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.... Read more
Affected Products : dboardgear- EPSS Score: %1.23
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3380
Multiple interpretation error in Panda Titanium 2005 4.02.01 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated... Read more
Affected Products : titanium_2005- EPSS Score: %0.79
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3369
Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and possibly upload files via the (1) fileid and (2) subkatid parameters.... Read more
Affected Products : burning_board- EPSS Score: %0.60
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3371
Multiple interpretation error in AVG 7 7.0.323 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe typ... Read more
Affected Products : avg_antivirus- EPSS Score: %0.45
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3383
SQL injection vulnerability in Techno Dreams Announcement script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.... Read more
Affected Products : announcement_script- EPSS Score: %2.10
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3370
Multiple interpretation error in ArcaVir 2005 package 2005-06-21 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be tre... Read more
Affected Products : arcavir_2005- EPSS Score: %0.45
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-2930
Stack-based buffer overflow in the _chm_find_in_PMGL function in chm_lib.c for chmlib before 0.36, as used in products such as KchmViewer, allows user-assisted attackers to execute arbitrary code via a CHM file containing a long element, a different vulne... Read more
Affected Products : chm_lib- EPSS Score: %2.08
- Published: Oct. 28, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3361
Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the nome parameter in a login operation, a variant of CVE-2005-3306.... Read more
Affected Products : flatnuke- EPSS Score: %0.34
- Published: Oct. 28, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2973
The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash).... Read more
Affected Products : linux_kernel- EPSS Score: %0.29
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3337
Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.... Read more
Affected Products : mantis- EPSS Score: %0.43
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3327
Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation protocol, and uses Operational mode without proving identi... Read more
Affected Products : data_ontap- EPSS Score: %0.94
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3245
Unspecified vulnerability in the ONC RPC dissector in Ethereal 0.10.3 to 0.10.12, when the "Dissect unknown RPC program numbers" option is enabled, allows remote attackers to cause a denial of service (memory consumption).... Read more
Affected Products : ethereal- EPSS Score: %2.62
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3322
Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).... Read more
- EPSS Score: %0.71
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3336
SQL injection vulnerability in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : mantis- EPSS Score: %1.34
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3243
Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.... Read more
Affected Products : ethereal- EPSS Score: %20.24
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3320
Cross-site scripting (XSS) vulnerability in SiteTurn Domain Manager Pro allows remote attackers to inject arbitrary web script or HTML via the err parameter in the panel script.... Read more
Affected Products : domain_manager_pro- EPSS Score: %0.40
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025