Latest CVE Feed
-
5.0
MEDIUMCVE-2005-3247
The SigComp UDVM in Ethereal 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3335
PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.... Read more
Affected Products : mantis- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2338
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in ... Read more
Affected Products : xoops- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3312
The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on t... Read more
Affected Products : internet_explorer- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3305
Multiple SQL injection vulnerabilities in Nuked Klan 1.7 allow remote attackers to execute arbitrary SQL commands via the (1) forum_id or (2) thread_id parameter in the Forum file, (3) the link_id in the Links file, (4) the artid parameter in the Sections... Read more
Affected Products : nuked-klan- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3309
Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php.... Read more
Affected Products : zomplog- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3304
Multiple SQL injection vulnerabilities in PHP-Nuke 7.8 allow remote attackers to modify SQL queries and execute arbitrary PHP code via (1) the username parameter in the Your Account page, (2) the url parameter in the Downloads module, and (3) the descript... Read more
Affected Products : php-nuke- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3311
BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : software_control-m_agent- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3307
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale parameter in a newtopic operation.... Read more
Affected Products : flatnuke- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3308
Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) comment parameter in detail.php, (3) the username parameter in get.php, and (4) the search parameter i... Read more
Affected Products : zomplog- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3306
Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vulnerability than CVE-2005-2814. NOTE: it is possible that... Read more
Affected Products : flatnuke- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
3.5
LOWCVE-2005-3310
Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by... Read more
Affected Products : phpbb- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2745
Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive information.... Read more
- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2746
Mail.app in Mail for Apple Mac OS X 10.3.9 and 10.4.2 includes message contents when using auto-reply rules, which could cause Mail.app to include decrypted message contents for encrypted messages.... Read more
- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2742
SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physical access to gain access to the des... Read more
- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2524
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.... Read more
- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2743
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.... Read more
- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2741
Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should be restricted to administrators.... Read more
- Published: Oct. 26, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2747
Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrary code via a crafted GIF file.... Read more
- Published: Oct. 25, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2748
The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application.... Read more
- Published: Oct. 25, 2005
- Modified: Apr. 03, 2025