Latest CVE Feed
-
3.6
LOWCVE-2005-3070
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.... Read more
Affected Products : hylafax- EPSS Score: %0.07
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3074
SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.... Read more
Affected Products : rsyslogd- EPSS Score: %0.43
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3076
Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid, (3) cid, or (4) m parameters to archive.php, or the (5) blogid parameter to blogadmin.php.... Read more
Affected Products : simplog- EPSS Score: %0.74
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3061
Multiple stack-based buffer overflows in PowerArchiver 8.10 through 9.5 Beta 4 and Beta 5 allow remote attackers to execute arbitrary code via a long filename in a (1) ACE or (2) ARJ archive.... Read more
- EPSS Score: %3.85
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3075
SQL injection vulnerability in Zengaia before 0.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : zengaia- EPSS Score: %0.43
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3064
MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or delete the message of the day (motd.txt).... Read more
Affected Products : multitheftauto- EPSS Score: %3.79
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3065
MultiTheftAuto 0.5 patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted command 40 that causes a -1 length to be used and triggers an out-of-bounds read.... Read more
Affected Products : multitheftauto- EPSS Score: %0.89
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3071
Unspecified vulnerability in Unix File System (UFS) on Solaris 8 and 9, when logging is enabled, allows local users to cause a denial of service ("soft hang") via certain write operations to UFS.... Read more
- EPSS Score: %0.06
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3054
fopen_wrappers.c in PHP 4.4.0, and possibly other versions, does not properly restrict access to other directories when the open_basedir directive includes a trailing slash, which allows PHP scripts in one directory to access files in other directories wh... Read more
Affected Products : php- EPSS Score: %0.57
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3059
Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-revalidate cache directive for HTTPS pages" or (2) a "display issue with cookie comment encoding."... Read more
- EPSS Score: %0.46
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3053
The sys_set_mempolicy function in mempolicy.c in Linux kernel 2.6.x allows local users to cause a denial of service (kernel BUG()) via a negative first argument.... Read more
- EPSS Score: %0.10
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3055
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer referenc... Read more
- EPSS Score: %0.09
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3049
PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.72
- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3045
SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field.... Read more
Affected Products : my_little_forum- EPSS Score: %0.56
- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2005-3051
Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including Turbo Searcher, allows remote attackers to execute arbitrary code via a large ARJ block.... Read more
Affected Products : 7-zip- EPSS Score: %14.86
- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-3046
SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.60
- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3050
PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.41
- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3052
SQL injection vulnerability in module/down.inc.php in jportal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the search field to download.php.... Read more
Affected Products : jportal_web_portal- EPSS Score: %0.42
- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3047
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.41
- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-3048
Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field ... Read more
Affected Products : phpmyfaq- EPSS Score: %3.58
- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025