Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2094
Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which cause... Read more
Affected Products : one_web_server- EPSS Score: %1.56
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2106
Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.... Read more
Affected Products : drupal- EPSS Score: %5.24
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2107
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter.... Read more
Affected Products : wordpress- EPSS Score: %0.91
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2136
Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world-readable permissions for /etc/shadow and (2) world-writable permissions for /bin/busybox, which allows local users to obtain hashed passwords or execute arbitrar... Read more
- EPSS Score: %0.15
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2089
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes II... Read more
Affected Products : internet_information_services- EPSS Score: %31.00
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1917
kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.... Read more
Affected Products : kpopper- EPSS Score: %0.08
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2092
BEA Systems WebLogic 8.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes... Read more
Affected Products : weblogic_server- EPSS Score: %2.11
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2091
IBM WebSphere 5.1 and WebSphere 5.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which... Read more
Affected Products : websphere_application_server- EPSS Score: %1.65
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2138
Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.... Read more
Affected Products : comdev_ecommerce- EPSS Score: %0.33
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1923
The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to ... Read more
Affected Products : clamav- EPSS Score: %0.66
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1625
Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 for Unix allows remote attackers to execute arbitrary code via a PDF document with a long /Filespec tag.... Read more
Affected Products : acrobat_reader- EPSS Score: %15.00
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2109
wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use.... Read more
Affected Products : wordpress- EPSS Score: %1.08
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2115
Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-of-bounds operation.... Read more
Affected Products : soldier_of_fortune_2- EPSS Score: %0.76
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2081
Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.... Read more
Affected Products : asterisk- EPSS Score: %0.35
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2069
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sni... Read more
- EPSS Score: %2.84
- Published: Jun. 30, 2005
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2005-2059
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via ... Read more
Affected Products : ubb.threads- EPSS Score: %0.32
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2055
RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via "default settings of earlier Internet Explorer browsers".... Read more
- EPSS Score: %0.34
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2080
Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.... Read more
Affected Products : backup_exec- EPSS Score: %0.74
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-2057
Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to new... Read more
Affected Products : ubb.threads- EPSS Score: %1.17
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2071
traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).... Read more
Affected Products : solaris- EPSS Score: %0.22
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025