Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2005-2234

    Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.... Read more

    Affected Products : aix
    • EPSS Score: %0.05
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2229

    Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password... Read more

    Affected Products : blog_torrent
    • EPSS Score: %3.26
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2216

    PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.... Read more

    Affected Products : photogal_photo_gallery
    • EPSS Score: %2.43
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2245

    Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers.... Read more

    Affected Products : tmos
    • EPSS Score: %0.85
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2239

    oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters.... Read more

    Affected Products : oftpd
    • EPSS Score: %3.31
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2244

    The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memo... Read more

    Affected Products : call_manager
    • EPSS Score: %1.38
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2005-2235

    Buffer overflow in the diagTasksWebSM command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.... Read more

    Affected Products : aix
    • EPSS Score: %0.06
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2241

    Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote a... Read more

    Affected Products : call_manager
    • EPSS Score: %0.66
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2005-2236

    Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.... Read more

    Affected Products : aix
    • EPSS Score: %0.61
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 7.2

    HIGH
    CVE-2005-2227

    Softiacom wMailserver 1.0 stores passwords in plaintext in the Darsite\MAILSRV\Admin key, which allows local users to gain administrator privileges.... Read more

    Affected Products : wmailserver
    • EPSS Score: %0.07
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2198

    PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.... Read more

    Affected Products : spid
    • EPSS Score: %2.96
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2181

    Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.... Read more

    • EPSS Score: %0.36
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2200

    Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication.... Read more

    • EPSS Score: %0.69
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2005-2201

    Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.... Read more

    • EPSS Score: %0.41
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2190

    Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp... Read more

    Affected Products : comersus_cart
    • EPSS Score: %0.43
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-2187

    McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in r... Read more

    • EPSS Score: %0.31
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2178

    probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter. NOTE: it is unclear which product or vendor this program is associated with, if any.... Read more

    Affected Products : probe.cgi
    • EPSS Score: %2.10
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2205

    The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.... Read more

    Affected Products : pngren
    • EPSS Score: %2.03
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 1.9

    LOW
    CVE-2005-2186

    Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.... Read more

    • EPSS Score: %0.11
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
  • 6.4

    MEDIUM
    CVE-2005-2212

    Backup Manager 0.5.8a creates an archive repository with world readable and writable permissions, which allows attackers to modify or read the repository.... Read more

    Affected Products : backup_manager
    • EPSS Score: %0.26
    • Published: Jul. 11, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 291739 Results