Latest CVE Feed
-
2.1
LOWCVE-2005-3568
db2fmp process in IBM DB2 Content Manager before 8.2 Fix Pack 10 allows local users to cause a denial of service (CPU consumption) by importing a corrupted Microsoft Excel file, aka "CORRUPTED EXEL FILE WILL CAUSE TEXT SEARCH PROCESS LOOPING."... Read more
Affected Products : db2_content_manager- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3588
SQL injection vulnerability in admin.php in Advanced Guestbook 2.2 allows remote attackers to execute arbitrary SQL commands and gain privileges via the username field.... Read more
Affected Products : advanced_guestbook- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2005-3555
Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administrator privileges to execute arbitrary SQL commands via the id parameter in the (1) editattributes or (2) admin page.... Read more
Affected Products : phplist- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3574
PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter.... Read more
Affected Products : icms- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3576
ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.... Read more
Affected Products : walla_telesite- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-3548
Directory traversal vulnerability in Task Manager in Invision Power Board (IP.Board) 2.0.1 allows limited remote attackers to include files via a .. (dot dot) in the "Task PHP File To Run" field.... Read more
Affected Products : invision_board- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3586
content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the application to return an error.... Read more
Affected Products : mambo- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3596
SQL injection vulnerability in ASPKnowledgebase allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password fields in adminlogin.asp.... Read more
Affected Products : aspknowledgebase- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3564
envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.... Read more
Affected Products : hp-ux- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3550
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.... Read more
Affected Products : toendacms- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3552
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, ... Read more
Affected Products : phpkit- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3583
(1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font o... Read more
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3344
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.... Read more
Affected Products : horde- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3585
SQL injection vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the forum parameter.... Read more
Affected Products : phpwebthings- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3587
Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.... Read more
Affected Products : clamav- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3595
By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.... Read more
Affected Products : windows_xp- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3591
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFuncti... Read more
Affected Products : flash_player- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3580
QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.... Read more
Affected Products : qdbm- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3556
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) t... Read more
Affected Products : phplist- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2005-3567
slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.... Read more
Affected Products : tivoli_directory_server- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025