Latest CVE Feed
-
7.5
HIGHCVE-2005-2252
PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.... Read more
Affected Products : phpauction- EPSS Score: %0.57
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2254
Multiple cross-site scripting (XSS) vulnerabilities in PhpAuction 2.5 allow remote attackers to inject arbitrary web script or HTML via the lan parameter to (1) index.php or (2) admin/index.php, or (3) the auction_id parameter to profile.php. NOTE: there... Read more
Affected Products : phpauction- EPSS Score: %0.39
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2255
Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php.... Read more
Affected Products : phpauction- EPSS Score: %0.26
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2266
Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive i... Read more
- EPSS Score: %1.95
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2264
Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.... Read more
Affected Products : firefox- EPSS Score: %3.23
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2274
Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofi... Read more
Affected Products : internet_explorer- EPSS Score: %22.08
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2271
iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."... Read more
Affected Products : icab- EPSS Score: %0.35
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2270
Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.... Read more
- EPSS Score: %36.18
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1219
Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.... Read more
Affected Products : image_color_management- EPSS Score: %77.99
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2247
Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.... Read more
Affected Products : moodle- EPSS Score: %0.45
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2240
xpvm.tcl in xpvm 1.2.5 allows local users to overwrite arbitrary files via a symlink attack on the xpvm.trace.$user temporary file.... Read more
Affected Products : xpvm- EPSS Score: %0.10
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2226
Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.... Read more
Affected Products : outlook_express- EPSS Score: %32.27
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2219
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.... Read more
Affected Products : hosting_controller- EPSS Score: %0.26
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2215
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.x before 1.4.6 and 1.5 before 1.5beta3 allows remote attackers to inject arbitrary web script or HTML via a parameter in the page move template, a different vulnerability than CVE-2005-1888.... Read more
Affected Products : mediawiki- EPSS Score: %0.35
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0564
Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.... Read more
Affected Products : word- EPSS Score: %33.67
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2224
aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.... Read more
Affected Products : asp.net- EPSS Score: %10.94
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2246
Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code via the (1) doc_path parameter to getpage.php or (2) set_menu parameter to lib/static/header.php.... Read more
Affected Products : iphotoalbum- EPSS Score: %11.16
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2243
Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote attackers to cause a denial of service (memory consumpt... Read more
Affected Products : call_manager- EPSS Score: %0.66
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2230
Electronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats temporary file insecurely, which allows local users to overwrite arbitrary files.... Read more
Affected Products : elmo- EPSS Score: %0.08
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2221
Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parame... Read more
Affected Products : dragonfly_commerce- EPSS Score: %0.43
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025