Latest CVE Feed
-
4.9
MEDIUMCVE-2005-3857
The time_out_leases function in locks.c for Linux kernel before 2.6.15-rc3 allows local users to cause a denial of service (kernel log message consumption) by causing a large number of broken leases, which is recorded to the log using the printk function.... Read more
- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-3856
The Popular URL capability (popularurls.cpp) in Krusader 1.60.0 and 1.70.0-beta1 saves passwords in cleartext in the krusaderrc file when the user enters URLs containing passwords in the panel URL field, which might allow attackers to access other sites.... Read more
Affected Products : krusader- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3854
Cross-site scripting (XSS) vulnerability in index.php in EasyPageCMS allows remote attackers to inject arbitrary web script or HTML via the cat parameter.... Read more
Affected Products : easypagecms- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3855
SQL injection vulnerability in process.php in 1-2-3 music store allows remote attackers to execute arbitrary SQL commands via the AlbumID parameter.... Read more
Affected Products : 1-2-3_music_store- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3852
SQL injection vulnerability in search.asp in Online Work Order Suite (OWOS) Lite Edition for ASP 3.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.... Read more
Affected Products : owos_lite- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3851
Cross-site scripting (XSS) vulnerability in search.asp in Online Attendance System (OASYS) Lite 1.0 allows remote attackers to inject arbitrary web script or HTML via certain search parameters, possibly the keyword parameter.... Read more
Affected Products : oasys_lite- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3850
Cross-site scripting (XSS) vulnerability in search.asp in Online Knowledge Base System (OKBSYS) Lite Edition 1.0 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the q parameter.... Read more
Affected Products : okbsys_lite- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3853
SQL injection vulnerability in snews.php in sNews 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category parameters to index.php.... Read more
Affected Products : snews- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2005-3847
The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is performing a cor... Read more
- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3848
Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST le... Read more
- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3849
Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter.... Read more
Affected Products : pmwiki- Published: Nov. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3841
Cross-site scripting (XSS) vulnerability in kPlaylist 1.6 (build 400), and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchfor search parameter.... Read more
Affected Products : kplaylist- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3838
Multiple SQL injection vulnerabilities in search.php in IsolSoft Support Center 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) lorder, (2) Priority, (3) Status, (4) Category, (5) searchvalue, and (6) field parameter.... Read more
Affected Products : support_center- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3840
SQL injection vulnerability in kb.php in Omnistar Live 5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) id and (2) category_id parameter. NOTE: due to a typo, an Internet Explorer issue was incorrectly assigned this i... Read more
Affected Products : omnistar_live- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3845
SQL injection vulnerability in invoices.php in EZ Invoice Inc 2.0 allows remote attackers to execute arbitrary SQL commands via the i parameter. NOTE: the vendor has stated "EZ Invoice, Inc has a patah available. Please email [email protected] an... Read more
Affected Products : ez_invoice_inc- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3843
SQL injection vulnerability in faq.php in Nicecoder iDesk 1.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.... Read more
Affected Products : idesk- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3839
Cross-site scripting (XSS) vulnerability in SupportPRO Supportdesk allows remote attackers to inject arbitrary web script or HTML via the (1) post tickers and (2) view tickets options.... Read more
Affected Products : supportdesk- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3842
SQL injection vulnerability in index.php in pdjk-support suite 1.1a and earlier allows remote attackers to execute arbitrary SQL commands via the (1) rowstart, (2) news_id, and (3) faq_id parameters.... Read more
Affected Products : pdjk-support_suite- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3844
SQL injection vulnerability in phpWordPress PHP News and Article Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the (1) poll and (2) category parameters to index.php, and (3) the ctg parameter in an archive action.... Read more
Affected Products : php_news_and_article_manager- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3846
SQL injection vulnerability in news.php in Fantastic News 2.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter.... Read more
Affected Products : fantastic_news- Published: Nov. 26, 2005
- Modified: Apr. 03, 2025