Latest CVE Feed
-
2.1
LOWCVE-2005-3331
viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : mgdiff_patch_viewer- EPSS Score: %0.09
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3329
Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operation.... Read more
Affected Products : authentication_agent_for_web- EPSS Score: %0.88
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3339
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.... Read more
Affected Products : mantis- EPSS Score: %0.06
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3248
Unspecified vulnerability in the X11 dissector in Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (divide-by-zero) via unknown vectors.... Read more
Affected Products : ethereal- EPSS Score: %3.22
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3335
PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.... Read more
Affected Products : mantis- EPSS Score: %6.97
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-3249
Unspecified vulnerability in the WSP dissector in Ethereal 0.10.1 to 0.10.12 allows remote attackers to cause a denial of service or corrupt memory via unknown vectors that cause Ethereal to free an invalid pointer.... Read more
Affected Products : ethereal- EPSS Score: %4.82
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3241
Multiple vulnerabilities in Ethereal 0.10.12 and earlier allow remote attackers to cause a denial of service (memory consumption) via unspecified vectors in the (1) ISAKMP, (2) FC-FCS, (3) RSVP, and (4) ISIS LSP dissector.... Read more
Affected Products : ethereal- EPSS Score: %3.89
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3316
The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting ... Read more
- EPSS Score: %0.90
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2005-3265
Buffer overflow in Skype for Windows 1.1.x.0 through 1.4.x.83 allows remote attackers to execute arbitrary code via (1) callto:// and (2) skype:// links, or (3) a non-standard VCARD, possibly due to an underlying error in the SysUtils.WideFmtStr Delphi ro... Read more
- EPSS Score: %35.55
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3323
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.... Read more
- EPSS Score: %2.30
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3333
SQL injection vulnerability in eBASEweb 3.0 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : ebaseweb- EPSS Score: %0.96
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3326
SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.... Read more
Affected Products : mybulletinboard- EPSS Score: %0.56
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3338
Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.... Read more
Affected Products : mantis- EPSS Score: %0.59
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3330
The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, ... Read more
Affected Products : snoopy- EPSS Score: %21.31
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3244
The BER dissector in Ethereal 0.10.3 to 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.... Read more
Affected Products : ethereal- EPSS Score: %7.07
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3247
The SigComp UDVM in Ethereal 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.... Read more
Affected Products : ethereal- EPSS Score: %3.16
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3246
Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (null dereference) via unknown vectors in the (1) SCSI, (2) sFlow, or (3) RTnet dissectors.... Read more
Affected Products : ethereal- EPSS Score: %3.22
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2338
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in ... Read more
Affected Products : xoops- EPSS Score: %1.30
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3312
The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on t... Read more
Affected Products : internet_explorer- EPSS Score: %27.24
- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3305
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_id parameter in the Forum file, (3) the link_id in the Links file, (4) the artid parameter in the Sections... Read more
Affected Products : nuked-klan- EPSS Score: %3.37
- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025