Latest CVE Feed
-
5.0
MEDIUMCVE-2005-2223
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.... Read more
- EPSS Score: %10.57
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2237
Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : aix- EPSS Score: %0.05
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2238
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.... Read more
Affected Products : aix- EPSS Score: %0.14
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2225
Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation. NOTE: it has bee... Read more
Affected Products : msn_messenger_service- EPSS Score: %11.12
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2245
Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers.... Read more
Affected Products : tmos- EPSS Score: %0.85
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2216
PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.... Read more
Affected Products : photogal_photo_gallery- EPSS Score: %2.43
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2229
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password... Read more
Affected Products : blog_torrent- EPSS Score: %3.26
- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2205
The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.... Read more
Affected Products : pngren- EPSS Score: %2.03
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2212
Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository.... Read more
Affected Products : backup_manager- EPSS Score: %0.26
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2005-2186
Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.... Read more
Affected Products : intrushield_security_management_system- EPSS Score: %0.11
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2197
SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php.... Read more
Affected Products : id_board- EPSS Score: %0.60
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2201
Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.... Read more
- EPSS Score: %0.41
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2200
Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.... Read more
- EPSS Score: %0.69
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2181
Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.... Read more
- EPSS Score: %0.36
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2214
apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.... Read more
Affected Products : apt-setup- EPSS Score: %0.05
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2190
Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp... Read more
Affected Products : comersus_cart- EPSS Score: %0.43
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1848
The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.... Read more
- EPSS Score: %0.98
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2180
gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.... Read more
Affected Products : gnats- EPSS Score: %0.07
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2189
Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.... Read more
Affected Products : securelinx- EPSS Score: %0.31
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2203
login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.... Read more
Affected Products : phpwishlist- EPSS Score: %0.57
- Published: Jul. 11, 2005
- Modified: Apr. 03, 2025