Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3361
Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the nome parameter in a login operation, a variant of CVE-2005-3306.... Read more
Affected Products : flatnuke- Published: Oct. 28, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2973
The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash).... Read more
Affected Products : linux_kernel- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-3249
Unspecified vulnerability in the WSP dissector in Ethereal 0.10.1 to 0.10.12 allows remote attackers to cause a denial of service or corrupt memory via unknown vectors that cause Ethereal to free an invalid pointer.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3241
Multiple vulnerabilities in Ethereal 0.10.12 and earlier allow remote attackers to cause a denial of service (memory consumption) via unspecified vectors in the (1) ISAKMP, (2) FC-FCS, (3) RSVP, and (4) ISIS LSP dissector.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3337
Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.... Read more
Affected Products : mantis- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3243
Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3322
Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).... Read more
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3335
PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.... Read more
Affected Products : mantis- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3245
Unspecified vulnerability in the ONC RPC dissector in Ethereal 0.10.3 to 0.10.12, when the "Dissect unknown RPC program numbers" option is enabled, allows remote attackers to cause a denial of service (memory consumption).... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3327
Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation protocol, and uses Operational mode without proving identi... Read more
Affected Products : data_ontap- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2005-3265
Buffer overflow in Skype for Windows 1.1.x.0 through 1.4.x.83 allows remote attackers to execute arbitrary code via (1) callto:// and (2) skype:// links, or (3) a non-standard VCARD, possibly due to an underlying error in the SysUtils.WideFmtStr Delphi ro... Read more
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3244
The BER dissector in Ethereal 0.10.3 to 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3331
viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : mgdiff_patch_viewer- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3329
Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operation.... Read more
Affected Products : authentication_agent_for_web- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3339
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.... Read more
Affected Products : mantis- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3088
fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.... Read more
Affected Products : fetchmail- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3334
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 p... Read more
Affected Products : flyspray- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3267
Integer overflow in Skype client before 1.4.x.84 on Windows, before 1.3.x.17 on Mac OS, before 1.2.x.18 on Linux, and 1.1.x.6 and earlier allows remote attackers to cause a denial of service (crash) via crafted network data with a large Object Counter val... Read more
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3330
The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, ... Read more
Affected Products : snoopy- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3332
PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via the match parameter.... Read more
Affected Products : vcard- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025