Latest CVE Feed
-
5.0
MEDIUMCVE-2005-2371
Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was prob... Read more
Affected Products : reports- EPSS Score: %3.63
- Published: Jul. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2374
Belkin 54g wireless routers do not properly set an administrative password, which allows remote attackers to gain access via the (1) Telnet or (2) web administration interfaces.... Read more
Affected Products : belkin_54g_wireless_router- EPSS Score: %0.85
- Published: Jul. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2376
Buffer overflow in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via a long (1) nickname or (2) chat message.... Read more
Affected Products : toca_race_driver- EPSS Score: %0.86
- Published: Jul. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1849
inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced.... Read more
Affected Products : zlib- EPSS Score: %8.98
- Published: Jul. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1852
Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an incom... Read more
- EPSS Score: %5.58
- Published: Jul. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2369
Multiple integer signedness errors in libgadu, as used in ekg before 1.6rc2 and other packages, may allow remote attackers to cause a denial of service or execute arbitrary code.... Read more
Affected Products : ekg- EPSS Score: %1.96
- Published: Jul. 26, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2329
MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to access the consoles of other users.... Read more
- EPSS Score: %0.44
- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2327
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.... Read more
Affected Products : e107- EPSS Score: %0.43
- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2330
Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.... Read more
Affected Products : oscommerce- EPSS Score: %10.02
- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2328
PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.... Read more
Affected Products : laffer- EPSS Score: %0.45
- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2332
Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a allows remote attackers to inject arbitrary web script or HTML via the username parameter to (1) admin.php or (2) login.php.... Read more
Affected Products : phppageprotect- EPSS Score: %0.41
- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2333
Cross-site scripting (XSS) vulnerability in smilies_popup.php in SEO-Board 1.0 allows remote attackers to inject arbitrary web script or HTML via the doc parameter.... Read more
Affected Products : seo-board- EPSS Score: %0.41
- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2334
Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.... Read more
Affected Products : y.sak- EPSS Score: %2.46
- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2331
PHP remote file inclusion vulnerability in display.php in MooseGallery allows remote attackers to execute arbitrary PHP code via the type parameter.... Read more
Affected Products : moosegallery- EPSS Score: %0.46
- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2318
Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : dvbbs- EPSS Score: %0.35
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2302
PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion... Read more
Affected Products : powerdns- EPSS Score: %0.01
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2304
Microsoft MSN Messenger 9.0 and Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) via an image with an ICC Profile with a large Tag Count.... Read more
- EPSS Score: %11.95
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2319
PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.... Read more
Affected Products : yawp- EPSS Score: %0.52
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1530
Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value.... Read more
- EPSS Score: %5.98
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2298
BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning... Read more
Affected Products : bitdefender_engine- EPSS Score: %0.22
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025