Latest CVE Feed
-
2.1
LOWCVE-2005-2311
SMS 1.9.2m and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) request1 or (2) request2 temporary files.... Read more
Affected Products : sms- EPSS Score: %0.08
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2318
Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : dvbbs- EPSS Score: %0.35
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2323
Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattach.php, (2) viewuser_id parameter to users.php, or the (3... Read more
- EPSS Score: %0.75
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2322
Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allows remote attackers to inject arbitrary web script or HTML via the (1) viewuser_id or (2) group parameter to users.php.... Read more
- EPSS Score: %0.73
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2297
Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter.... Read more
Affected Products : easerver- EPSS Score: %71.53
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2309
Opera 8.01 allows remote attackers to cause a denial of service (CPU consumption) via a crafted JPEG image, as demonstrated using random.jpg.... Read more
Affected Products : opera_browser- EPSS Score: %1.86
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2312
management.php in Realnode Emilda 1.2.2 and earlier allows remote attackers to perform actions as other users by modifying the user_id parameter.... Read more
Affected Products : emilda- EPSS Score: %0.72
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2314
inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator's username and password by setting the do_login parameter and performing an edit action using user.php, which causes the login check to be bypassed and leaks the... Read more
Affected Products : phpsftpd- EPSS Score: %0.71
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2305
DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via a long message to TCP port 1071 or 1073, possibly due to a buffer overflow.... Read more
Affected Products : remote_control_server- EPSS Score: %7.31
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1530
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.... Read more
- EPSS Score: %5.98
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2319
PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.... Read more
Affected Products : yawp- EPSS Score: %0.52
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2304
Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.... Read more
- EPSS Score: %11.95
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2196
The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.... Read more
Affected Products : airport_card- EPSS Score: %0.07
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2307
netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."... Read more
- EPSS Score: %46.80
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2005-2310
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.... Read more
Affected Products : winamp- EPSS Score: %7.72
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2326
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php.... Read more
Affected Products : clever_copy- EPSS Score: %0.34
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2301
PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack.... Read more
Affected Products : powerdns- EPSS Score: %0.07
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2298
BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning... Read more
Affected Products : bitdefender_engine- EPSS Score: %0.22
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1851
A certain contributed script for ekg Gadu Gadu client 1.5 and earlier allows attackers to execute shell commands via unknown attack vectors.... Read more
Affected Products : ekg- EPSS Score: %0.45
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1850
Certain contributed scripts for ekg Gadu Gadu client 1.5 and earlier create temporary files insecurely, with unknown impact and attack vectors, a different vulnerability than CVE-2005-1916.... Read more
Affected Products : ekg- EPSS Score: %0.45
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025