Latest CVE Feed
-
4.3
MEDIUMCVE-2005-1999
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter i... Read more
Affected Products : pafiledb- EPSS Score: %0.41
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1997
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.... Read more
Affected Products : mcgallery- EPSS Score: %0.40
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1213
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.... Read more
Affected Products : outlook_express- EPSS Score: %83.91
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0488
Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.... Read more
- EPSS Score: %10.25
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1215
Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.... Read more
Affected Products : isa_server- EPSS Score: %12.44
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1208
Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflo... Read more
- EPSS Score: %44.79
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1937
A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was ori... Read more
- EPSS Score: %0.80
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1994
Finjan SurfinGate 7.0SP2 and SP3 allows remote attackers to download blocked files via hex-encoded characters in a filename, as demonstrated using "%2e".... Read more
Affected Products : surfingate- EPSS Score: %0.48
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0563
Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("javAsc
ript:") ... Read more
Affected Products : exchange_server- EPSS Score: %22.96
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1211
Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.... Read more
Affected Products : internet_explorer- EPSS Score: %43.44
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1214
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.... Read more
Affected Products : windows_2000 windows_2003_server windows_xp windows_98 windows_98se windows_me windows_2000_terminal_services- EPSS Score: %24.13
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1216
Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.... Read more
Affected Products : isa_server- EPSS Score: %33.90
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1212
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.... Read more
Affected Products : windows_2000 windows_2003_server windows_xp windows_98 windows_98se windows_me windows_2000_terminal_services- EPSS Score: %34.92
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1207
Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.... Read more
- EPSS Score: %1.27
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1205
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.... Read more
Affected Products : windows_2003_server- EPSS Score: %41.24
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1206
Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."... Read more
- EPSS Score: %57.97
- Published: Jun. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1474
Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.... Read more
- EPSS Score: %1.24
- Published: Jun. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1936
Unknown vulnerability in the web server for the ESS/ Network Controller for Xerox Document Centre 240 through 555 running System Software 27.18.017 and earlier allows attackers to "gain unauthorized access."... Read more
- EPSS Score: %0.67
- Published: Jun. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1933
Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.... Read more
Affected Products : mac_os_x- EPSS Score: %1.25
- Published: Jun. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1935
Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function... Read more
- EPSS Score: %27.21
- Published: Jun. 13, 2005
- Modified: Apr. 03, 2025