Latest CVE Feed
-
2.6
LOWCVE-2005-2414
Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remote attackers to cause a denial of service (application crash) via a large HTML file that loads a DOM call from within nested DIV tags, ... Read more
Affected Products : xpcom- EPSS Score: %5.00
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2417
Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.... Read more
Affected Products : contrexx- EPSS Score: %0.70
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2440
SQL injection vulnerability in login.asp in Thomson Web Skill Vantage Manager allows remote attackers to execute arbitrary SQL commands via the svmPassword parameter.... Read more
Affected Products : web_skill_vantage_manager- EPSS Score: %0.73
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2422
Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter.... Read more
Affected Products : beehive_forum- EPSS Score: %0.34
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2439
SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.... Read more
Affected Products : usebb- EPSS Score: %0.62
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2427
Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter.... Read more
Affected Products : cartwiz- EPSS Score: %0.43
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2424
The management interface for Siemens SANTIS 50 running firmware 4.2.8.0, and possibly other products including Ericsson HN294dp and Dynalink RTA300W, allows remote attackers to access the Telnet port without authentication via certain packets to the web i... Read more
Affected Products : santis_50- EPSS Score: %1.64
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2412
PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.... Read more
Affected Products : php_firstpost- EPSS Score: %3.20
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2444
Trillian Pro 3.1 build 121, when checking Yahoo e-mail, stores the password in plaintext in a world readable file and does not delete the file after login, which allows local users to obtain sensitive information.... Read more
Affected Products : trillian_pro- EPSS Score: %0.07
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2432
SQL injection vulnerability in PhpList allows remote attackers to modify SQL statements via the id argument to admin pages such as (1) members or (2) admin.... Read more
Affected Products : phplist- EPSS Score: %0.70
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2430
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to det... Read more
Affected Products : gforge- EPSS Score: %1.28
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2438
Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.... Read more
Affected Products : usebb- EPSS Score: %0.64
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2450
Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message.... Read more
Affected Products : clamav- EPSS Score: %3.64
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1853
gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.... Read more
Affected Products : gopher- EPSS Score: %0.05
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2426
FTPshell Server 3.38 allows remote authenticated users to cause a denial of service (application crash) by multiple connections and disconnections without using the QUIT command.... Read more
Affected Products : ftpshell_server- EPSS Score: %1.11
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2441
Multiple cross-site scripting (XSS) vulnerabilities in VBzoom allow remote attackers to inject arbitrary web script and HTML via the (1) UserName parameter to profile.php or (2) UserID parameter to login.php.... Read more
Affected Products : vbzoom- EPSS Score: %0.86
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2433
PhpList allows remote attackers to obtain sensitive information via a direct request to (1) about.php, (2) connect.php, (3) domainstats.php or (4) usercheck.php in public_html/lists/admin directory, (5) attributes.php, (6) dbcheck.php, (7) importcsv.php, ... Read more
Affected Products : phplist- EPSS Score: %1.36
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2423
Beehive Forum allows remote attackers to obtain sensitive information via (1) an invalid final_uri or sort_by parameter to index.php or a direct request to (2) admin.php, (3) attachments.inc.php, (4) banned.inc.php, (5) beehive.inc.php, (6) constants.inc.... Read more
Affected Products : beehive_forum- EPSS Score: %0.39
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2132
RPC portmapper (rpcbind) in SCO UnixWare 7.1.1 m5, 7.1.3 mp5, and 7.1.4 mp2 allows remote attackers or local users to cause a denial of service (lack of response) via multiple invalid portmap requests.... Read more
Affected Products : unixware- EPSS Score: %0.28
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2346
Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.... Read more
Affected Products : groupwise- EPSS Score: %2.05
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025