Latest CVE Feed
-
10.0
HIGHCVE-2005-1983
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application,... Read more
- EPSS Score: %87.82
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2362
Unknown vulnerability several dissectors in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a denial of service (application crash) by reassembling certain packets.... Read more
Affected Products : ethereal- EPSS Score: %1.34
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2541
Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.... Read more
Affected Products : tar- EPSS Score: %3.25
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2500
Buffer overflow in the xdr_xcode_array2 function in xdr.c in Linux kernel 2.6.12, as used in SuSE Linux Enterprise Server 9, might allow remote attackers to cause a denial of service and possibly execute arbitrary code via crafted XDR data for the nfsacl ... Read more
Affected Products : linux_kernel- EPSS Score: %2.58
- Published: Aug. 08, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2484
Buffer overflow in the rdb_query function for Denora IRC Stats 1.0 might allow attackers to execute arbitrary code.... Read more
Affected Products : denora_irc_stats- EPSS Score: %1.41
- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2487
Unknown vulnerability in Sun McData switches and directors 4300, 4500, 6064, and 6140 before E/OS 6.0.0 may allow attackers to cause a denial of service (connectivity and array access loss) via a network broadcast storm.... Read more
- EPSS Score: %0.07
- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2486
SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-200... Read more
Affected Products : portailphp- EPSS Score: %0.33
- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2488
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.... Read more
Affected Products : web_content_management_news_system- EPSS Score: %0.53
- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2482
The StateToOptions function in msfweb in Metasploit Framework 2.4 and earlier, when running with the -D option (defanged mode), allows attackers to modify temporary environment variables before the "_Defanged" environment option is checked when processing... Read more
Affected Products : metasploit_framework- EPSS Score: %0.49
- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2483
Eval injection vulnerability in Karrigell before 2.1.8 allows remote attackers to execute arbitrary Python code via modified arguments to a Karrigell services (.ks) script, which can reference functions from libraries that are used by that script.... Read more
Affected Products : karrigell- EPSS Score: %5.10
- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2485
Cross-site scripting (XSS) vulnerability in the Helpdesk in Logicampus before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : logicampus- EPSS Score: %0.35
- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2489
Web Content Management News System allows remote attackers to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.... Read more
Affected Products : web_content_management_news_system- EPSS Score: %1.80
- Published: Aug. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2481
ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character.... Read more
Affected Products : coldfusion_fusebox- EPSS Score: %0.30
- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2476
Cross-site scripting (XSS) vulnerability in lost_passowrd.php in Naxtor Shopping Cart 1.0 allows remote attackers to inject arbitrary web script or HTML via the email parameter.... Read more
Affected Products : shopping_cart- EPSS Score: %0.56
- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2359
The AES-XCBC-MAC algorithm in IPsec in FreeBSD 5.3 and 5.4, when used for authentication without other encryption, uses a constant key instead of the one that was assigned by the system administrator, which can allow remote attackers to spoof packets to e... Read more
Affected Products : freebsd- EPSS Score: %0.36
- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2474
ChurchInfo allows remote attackers to execute obtain sensitive information via the PersonID parameter to (1) PersonView.php, (2) MemberRoleChange.php, (3) PropertyAssign.php, (4) WhyCameEditor.php, (5) GroupPropsEditor.php, (6) Reports/PDFLabel.php, or (7... Read more
Affected Products : churchinfo- EPSS Score: %1.09
- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2480
Cross-site scripting (XSS) vulnerability in ColdFusion Fusebox 4.1.0 allows remote attackers to inject arbitrary web script or HTML via the fuseaction parameter, which is not quoted in an error page, as demonstrated using index.cfm.... Read more
Affected Products : coldfusion_fusebox- EPSS Score: %0.40
- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1268
Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null... Read more
- EPSS Score: %1.99
- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1767
traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).... Read more
- EPSS Score: %0.03
- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1854
Unknown vulnerability in apt-cacher in Debian 3.1, related to "missing input sanitising," allows remote attackers to execute arbitrary commands on the caching server.... Read more
Affected Products : apt-cacher- EPSS Score: %1.01
- Published: Aug. 05, 2005
- Modified: Apr. 03, 2025