Latest CVE Feed
-
5.0
MEDIUMCVE-2005-4079
The register_globals emulation in phpMyAdmin 2.7.0 rc1 allows remote attackers to exploit other vulnerabilities in phpMyAdmin by modifying the import_blacklist variable in grab_globals.php, which can then be used to overwrite other variables.... Read more
Affected Products : phpmyadmin- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3192
Heap-based buffer overflow in the StreamPredictor function in Xpdf 3.01, as used in products such as (1) Poppler, (2) teTeX, (3) KDE kpdf, and (4) pdftohtml, (5) KOffice KWord, (6) CUPS, and (7) libextractor allows remote attackers to execute arbitrary co... Read more
Affected Products : xpdf- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4078
Multiple cross-site scripting (XSS) vulnerabilities in Ideal BB.NET 1.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) forumID, (2) boardID, and (3) topicRepeater1-p parameters in topics.aspx, (4) boardID parameter i... Read more
Affected Products : ideal_bb.net- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4073
SQL injection vulnerability in view_archive.cfm in CFMagic Magic List Pro 2.5 allows remote attackers to execute arbitrary SQL commands via the ListID parameter.... Read more
Affected Products : magic_list_pro- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-4076
Buffer overflow in Appfluent Technology Database IDS 2.0 allows local users to execute arbitrary code via a long APPFLUENT_HOME environment variable.... Read more
Affected Products : database_ids- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4083
Directory traversal vulnerability in xs_edit.php in the eXtreme Styles phpBB module 2.2.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the edit parameter.... Read more
Affected Products : extreme_styles_phpbb_module- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4080
Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet ... Read more
Affected Products : imp- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4074
Directory traversal vulnerability in index.cfm in CF_Nuke 4.6 and earlier, when Sandbox Security is disabled, allows remote attackers to include arbitrary local .cfm files via a .. (dot dot) in the (1) sector or (2) page parameters.... Read more
Affected Products : cf_nuke- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4084
xs_edit.php in the phpBB eXtreme Styles module 2.2.1 and earlier allows remote attackers to obtain the installation path of the application via an invalid viewbackup parameter.... Read more
Affected Products : phpbb_extreme_styles- Published: Dec. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4060
Cross-site scripting (XSS) vulnerability in search.asp in rwAuction Pro 4.0 and 5.0 allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter.... Read more
Affected Products : rwauction_pro- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-4046
Unspecified vulnerability in Reverse SSL Proxy Plug-in for Sun Java System Application Server Standard Edition 7 2004Q2, Application Server Enterprise Edition 8.1 2005Q1, and Sun ONE Application Server 7 Standard Edition, as used in multiple web servers, ... Read more
- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4049
Multiple SQL injection vulnerabilities in Blog System 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the cat parameter in index.php and (2) the note parameter in blog.php.... Read more
Affected Products : blog_system- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4056
SQL injection vulnerability in search.php in PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) Location, (2) Last Name, and (3) First Name parameters.... Read more
Affected Products : pluggedout_nexus- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4052
e107 0.6174 allows remote attackers to redirect users to other web sites via the download parameter in rate.php, which is used after a user submits a file download rating. NOTE: in the default installation, the e_BASE variable restricts the redirection t... Read more
Affected Products : e107- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4063
Multiple cross-site scripting (XSS) vulnerabilities in NetAuctionHelp 3.0 and earlier allow remote attackers to inject arbitrary HTML and web script via the (1) L, (2) sort, (3) category, (4) categoryname parameters to search.asp.... Read more
Affected Products : netauctionhelp- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4051
e107 0.6174 allows remote attackers to vote multiple times for a download via repeated requests to rate.php.... Read more
Affected Products : e107- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4050
Buffer overflow in multiple Multi-Tech Systems MultiVOIP devices with firmware before x.08 allows remote attackers to execute arbitrary code via a long INVITE field in a Session Initiation Protocol (SIP) packet.... Read more
Affected Products : multivoip- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4061
Cross-site scripting (XSS) vulnerability in PASearch.asp in XcPhotoAlbum 1.x allows remote attackers to inject arbitrary web script or HTML via the search parameters.... Read more
Affected Products : xcphotoblbum- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4059
SQL injection vulnerability in searchdb.asp in LocazoList 1.03c and earlier allows remote attackers to execute arbitrary SQL commands via the q parameter.... Read more
Affected Products : locazolist- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4048
Heap-based buffer overflow in the avcodec_default_get_buffer function (utils.c) in FFmpeg libavcodec 0.4.9-pre1 and earlier, as used in products such as (1) mplayer, (2) xine-lib, (3) Xmovie, and (4) GStreamer, allows remote attackers to execute arbitrary... Read more
Affected Products : ffmpeg- Published: Dec. 07, 2005
- Modified: Apr. 03, 2025