Latest CVE Feed
-
5.0
MEDIUMCVE-2005-3923
NetObjects Fusion 9 (NOF9) allows remote attackers to obtain sensitive information, including passwords, by downloading the _versioning_repository_/rollbacklog.xml file, then using it to download and modify the associated ZIP file to edit and republish th... Read more
Affected Products : netobjects_fusion- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3924
SQL injection vulnerability in themes/kategorie/index.php in Randshop allows remote attackers to execute arbitrary SQL commands via the (1) kategorieid and (2) katid parameters.... Read more
Affected Products : randshop- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3920
SQL injection vulnerability in Babe Logger 2 allows remote attackers to execute arbitrary SQL commands via the (1) gal parameter to index.php or (2) id parameter to comments.php.... Read more
Affected Products : babe_logger- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3917
SQL injection vulnerability in usersession in CommodityRentals 2.0 Online Rental Business Creator script allows remote attackers to execute arbitrary SQL commands via the user_id parameter.... Read more
Affected Products : commodityrentals- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3909
SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the sortorder parameter.... Read more
Affected Products : post_affiliate_pro- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3926
Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via the _SERVER[REMOTE_ADDR] parameter, which is injected into a .inc script that ... Read more
Affected Products : guppy- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3905
Unspecified vulnerability in reflection APIs in Java SDK and JRE 1.3.1_15 and earlier, 1.4.2_08 and earlier, and JDK and JRE 5.0 Update 3 and earlier allows remote attackers to escape the Java sandbox and access arbitrary files or execute arbitrary applic... Read more
- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3915
The Internet Key Exchange version 1 (IKEv1) implementation in Clavister Client Web allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.... Read more
- Published: Nov. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3902
Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as d... Read more
Affected Products : virtual_hosting_control_system- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3900
Macromedia Breeze Communication Server and Breeze Live Server does 5.1 and earlier not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Fla... Read more
Affected Products : breeze- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3901
Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133)... Read more
Affected Products : flash_communication_server- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2005-3895
Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which al... Read more
Affected Products : otrs- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3896
Mozilla allows remote attackers to cause a denial of service (CPU consumption) via a Javascript BODY onload event that calls the window function.... Read more
Affected Products : mozilla- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3888
Memory leak in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service via multiple DCC packets with a code other than 2 and a large size field, which allocates memory for the packet but does not free it after the packet has been dropped.... Read more
Affected Products : gadu-gadu_instant_messenger- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3889
Gadu-Gadu 7.20 allows remote attackers to cause a denial of service via multiple DCC packets with a code of 6 or 7, which triggers a large number of popup windows to the user and creates a large number of threads.... Read more
Affected Products : gadu-gadu_instant_messenger- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3893
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login ... Read more
Affected Products : otrs- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.6
HIGHCVE-2005-2124
Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafte... Read more
- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3891
Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the "imgcache\" string that is added to the end of the buffe... Read more
Affected Products : gadu-gadu_instant_messenger- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
5.4
MEDIUMCVE-2005-3899
The automatic update feature in Google Talk allows remote attackers to cause a denial of service (CPU and memory consumption) by poisoning a target's DNS cache and causing a large update file to be sent, which consumes large amounts of CPU and memory duri... Read more
Affected Products : talk- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3892
Gadu-Gadu 7.20 allows remote attackers to eavesdrop on a user via a web page that accesses the EasycallLite.oce ActiveX control, which can initiate an outgoing phone call and listen to the microphone.... Read more
Affected Products : gadu-gadu_instant_messenger- Published: Nov. 29, 2005
- Modified: Apr. 03, 2025