Latest CVE Feed
-
2.6
LOWCVE-2005-1790
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismat... Read more
Affected Products : internet_explorer- EPSS Score: %84.75
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1837
Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.... Read more
Affected Products : fortinet_firewall- EPSS Score: %0.34
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1809
Sony Ericsson P900 Beamer allows remote attackers to cause a denial of service (panic) via an obexftp session with a long filename in an OBEX File Transfer or OBEX Object Push.... Read more
- EPSS Score: %1.04
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1788
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.... Read more
Affected Products : hosting_controller- EPSS Score: %0.29
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1817
Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.... Read more
Affected Products : invision_board- EPSS Score: %2.95
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1772
Buffer overflow in the client cd-key hash in Terminator 3: War of the Machines 1.16 and earlier allows remote attackers to cause a denial of service (application crash) via a long client cd-key hash value, a different vulnerability than CVE-2005-1556.... Read more
Affected Products : terminator_3_war_of_the_machines- EPSS Score: %0.97
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
8.4
HIGHCVE-2005-1831
Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able t... Read more
Affected Products : sudo- EPSS Score: %0.11
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1773
Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be SPLIT in the future when more precise technical details become available.... Read more
Affected Products : listserv- EPSS Score: %1.98
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1783
BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the result... Read more
Affected Products : bookreview- EPSS Score: %0.46
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1779
SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.... Read more
Affected Products : maxwebportal- EPSS Score: %0.26
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1778
Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.... Read more
Affected Products : postnuke- EPSS Score: %0.41
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1866
Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter.... Read more
Affected Products : calendarix_advanced- EPSS Score: %0.43
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1907
The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.... Read more
Affected Products : isa_server- EPSS Score: %25.48
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1796
Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code.... Read more
- EPSS Score: %7.88
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1781
Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).... Read more
- EPSS Score: %3.27
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1776
Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C'Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.... Read more
Affected Products : cnedra- EPSS Score: %4.76
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1770
Buffer overflow in the Aavmker4 device driver in Avast! Antivirus 4.6 and possibly other versions allows local users to cause a denial of service (system crash) and possibly execute arbitrary code via certain signals combined with crafted input.... Read more
Affected Products : avast_antivirus- EPSS Score: %0.06
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1833
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to calendar.php, (2) idsql parameter to online.php, (3) usersearch parameter to memberlist.php, (4... Read more
Affected Products : mybulletinboard- EPSS Score: %1.04
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1832
Multiple cross-site scripting (XSS) vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 and earlier allow remote attackers to execute arbitrary web script or HTML via the (1) forums, (2) version, or (3) limit parameter to misc.php, (4) page or (5) datecut ... Read more
Affected Products : mybulletinboard- EPSS Score: %0.43
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1799
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
- EPSS Score: %0.30
- Published: May. 31, 2005
- Modified: Apr. 03, 2025