Latest CVE Feed
-
5.0
MEDIUMCVE-2005-2244
The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memo... Read more
Affected Products : call_manager- EPSS Score: %1.38
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2236
Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.... Read more
Affected Products : aix- EPSS Score: %0.61
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2241
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote a... Read more
Affected Products : call_manager- EPSS Score: %0.66
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2227
Softiacom wMailserver 1.0 stores passwords in plaintext in the Darsite\MAILSRV\Admin key, which allows local users to gain administrator privileges.... Read more
Affected Products : wmailserver- EPSS Score: %0.07
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0564
Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.... Read more
Affected Products : word- EPSS Score: %33.67
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1219
Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.... Read more
Affected Products : image_color_management- EPSS Score: %77.99
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2229
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password... Read more
Affected Products : blog_torrent- EPSS Score: %3.26
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2216
PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.... Read more
Affected Products : photogal_photo_gallery- EPSS Score: %2.43
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2245
Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers.... Read more
Affected Products : tmos- EPSS Score: %0.85
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2235
Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : aix- EPSS Score: %0.06
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2238
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.... Read more
Affected Products : aix- EPSS Score: %0.14
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2223
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.... Read more
- EPSS Score: %10.57
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2225
Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation. NOTE: it has bee... Read more
Affected Products : msn_messenger_service- EPSS Score: %11.12
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2237
Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : aix- EPSS Score: %0.05
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2246
Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code via the (1) doc_path parameter to getpage.php or (2) set_menu parameter to lib/static/header.php.... Read more
Affected Products : iphotoalbum- EPSS Score: %11.16
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2243
Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumpt... Read more
Affected Products : call_manager- EPSS Score: %0.66
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2230
Electronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats temporary file insecurely, which allows local users to overwrite arbitrary files.... Read more
Affected Products : elmo- EPSS Score: %0.08
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2221
Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parame... Read more
Affected Products : dragonfly_commerce- EPSS Score: %0.43
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1859
Unknown vulnerability in arshell in the Array Service (arrayd) for SGI ProPack 3 with SP 5 and 6, and SGI ProPack 4, allows local users to execute arbitrary shells as root on other hosts in the cluster or array.... Read more
Affected Products : propack- EPSS Score: %0.05
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2233
Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or ... Read more
Affected Products : aix- EPSS Score: %0.05
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025