Latest CVE Feed
-
6.4
MEDIUMCVE-2005-2255
Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php.... Read more
Affected Products : phpauction- EPSS Score: %0.26
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2252
PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.... Read more
Affected Products : phpauction- EPSS Score: %0.57
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2268
Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog... Read more
- EPSS Score: %2.16
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-2262
Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascrip... Read more
Affected Products : firefox- EPSS Score: %16.00
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2257
The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter.... Read more
Affected Products : phpslash- EPSS Score: %1.19
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2266
Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive i... Read more
- EPSS Score: %1.95
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2253
SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this descr... Read more
Affected Products : phpauction- EPSS Score: %0.52
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2259
The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote atta... Read more
- EPSS Score: %3.55
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2272
Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vuln... Read more
Affected Products : safari- EPSS Score: %1.25
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2249
Multiple unknown vulnerabilities in Jinzora 2.0.1 have unknown impact and attack vectors, possibly involving a PHP file inclusion vulnerability.... Read more
Affected Products : jinzora- EPSS Score: %0.46
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2231
High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : heartbeat- EPSS Score: %0.10
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2216
PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.... Read more
Affected Products : photogal_photo_gallery- EPSS Score: %2.43
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2229
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password... Read more
Affected Products : blog_torrent- EPSS Score: %3.26
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2245
Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers.... Read more
Affected Products : tmos- EPSS Score: %0.85
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2227
Softiacom wMailserver 1.0 stores passwords in plaintext in the Darsite\MAILSRV\Admin key, which allows local users to gain administrator privileges.... Read more
Affected Products : wmailserver- EPSS Score: %0.07
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2241
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote a... Read more
Affected Products : call_manager- EPSS Score: %0.66
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2236
Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.... Read more
Affected Products : aix- EPSS Score: %0.61
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2234
Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : aix- EPSS Score: %0.05
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2228
Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.... Read more
Affected Products : web_wiz_forums- EPSS Score: %0.31
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2244
The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memo... Read more
Affected Products : call_manager- EPSS Score: %1.38
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025