Latest CVE Feed
-
5.0
MEDIUMCVE-2005-3811
Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to overwrite arbitrary files with session information via the sid parameter.... Read more
Affected Products : magic_winmail_server- Published: Nov. 25, 2005
- Modified: Apr. 03, 2025
-
6.6
MEDIUMCVE-2005-3806
The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by tri... Read more
- Published: Nov. 25, 2005
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2005-3807
Memory leak in the VFS file lease handling in locks.c in Linux kernels 2.6.10 to 2.6.15 allows local users to cause a denial of service (memory exhaustion) via certain Samba activities that cause an fasync entry to be re-allocated by the fcntl_setlease fu... Read more
Affected Products : linux_kernel- Published: Nov. 25, 2005
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2005-3808
Integer overflow in the invalidate_inode_pages2_range function in mm/truncate.c in Linux kernel 2.6.11 to 2.6.14 allows local users to cause a denial of service (hang) via 64-bit mmap calls that are not properly handled on a 32-bit system.... Read more
Affected Products : linux_kernel- Published: Nov. 25, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3810
ip_conntrack_proto_icmp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via a message without ICMP ID (ICMP_ID) information, which leads to a null dereference.... Read more
Affected Products : linux_kernel- Published: Nov. 25, 2005
- Modified: Apr. 03, 2025
-
4.9
MEDIUMCVE-2005-3805
A locking problem in POSIX timer cleanup handling on exit in Linux kernel 2.6.10 to 2.6.14, when running on SMP systems, allows local users to cause a denial of service (deadlock) involving process CPU timers.... Read more
Affected Products : linux_kernel- Published: Nov. 25, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3809
The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information, which triggers a null derefer... Read more
Affected Products : linux_kernel- Published: Nov. 25, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3800
Macromedia Contribute Publishing Server (CPS) before 1.11 uses a weak algorithm to encrypt user password in connection keys that use shared FTP login credentials, which allows attackers to obtain sensitive information.... Read more
Affected Products : contribute_publishing_server- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3794
AlstraSoft Affiliate Network Pro 7.2 allows remote attackers to obtain sensitive information via a direct request to scripts such as (1) togateway.php and (2) other unspecified scripts.... Read more
Affected Products : affiliate_network_pro- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3802
Belkin F5D7232-4 and F5D7230-4 wireless routers with firmware 4.03.03 and 4.05.03, when a legitimate administrator is logged into the web management interface, allow remote attackers to access the management interface without authentication.... Read more
- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3792
Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with patch 3.1, allows remote attackers to execute arbitrary SQL commands, as demonstrated via the query parameter in a stories type.... Read more
Affected Products : php-nuke- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3803
Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information.... Read more
- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-3804
Cisco IP Phone (VoIP) 7920 1.0(8) listens to UDP port 17185 to support a VxWorks debugger, which allows remote attackers to obtain sensitive information and cause a denial of service.... Read more
Affected Products : 7920_wireless_ip_phone- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3790
Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) i and (2) text parameters.... Read more
Affected Products : phpwcms- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3798
SQL injection vulnerability in admin/index.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary SQL commands via the username field.... Read more
Affected Products : template_seller- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3795
Multiple cross-site scripting (XSS) vulnerabilities in AlstraSoft Affiliate Network Pro 7.2 allow remote attackers to inject arbitrary web script or HTML via (1) the Err parameter in admin/index.php and the (2) firstname and (3) lastname parameters in ind... Read more
Affected Products : affiliate_network_pro- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3789
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) form_lang parameter in login.php and (2) the imgdir parameter in random_image.php.... Read more
Affected Products : phpwcms- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3797
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attackers to execute arbitrary PHP code via the config[basepath] parameter.... Read more
Affected Products : template_seller- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-3801
CounterPane PasswordSafe 1.x and 2.x allows local users to test possible encryption keys against a subset of the stored key data without performing the more expensive key derivation function (KDF) function, which reduces the search time in brute force att... Read more
Affected Products : passwordsafe- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3791
HTTP response splitting vulnerability in phpAdsNew and phpPgAds 2.0.6 and earlier allows remote attackers to inject arbitrary HTML headers via adclick.php and possibly other unspecified vectors.... Read more
- Published: Nov. 24, 2005
- Modified: Apr. 03, 2025