Latest CVE Feed
-
7.5
HIGHCVE-2005-1475
The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.... Read more
Affected Products : opera_browser- EPSS Score: %0.38
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1769
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.0 through 1.4.4 allow remote attackers to inject arbitrary web script or HTML via unknown attack vectors in (1) the URL or (2) an e-mail message.... Read more
- EPSS Score: %1.64
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2003
Ultimate PHP Board (UPB) 1.9.6 GOLD allows remote attackers to obtain sensitive information via an invalid (zero) id parameter to (1) viewtopic.php, (2) profile.php, or (3) newpost.php, which reveals the path in an error message.... Read more
Affected Products : ultimate_php_board- EPSS Score: %0.35
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1669
Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to inject arbitrary web script or HTML via "javascript:" URLs when a new window or frame is opened, which allows remote attackers to bypass access restrictions ... Read more
Affected Products : opera_browser- EPSS Score: %0.44
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1952
Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequence in the URL, which results in an incorrect directory d... Read more
Affected Products : pico_server- EPSS Score: %1.73
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1269
Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.... Read more
- EPSS Score: %2.51
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1963
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.... Read more
Affected Products : cerberus_helpdesk- EPSS Score: %0.59
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2026
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.... Read more
Affected Products : vertical_horizon-2402s- EPSS Score: %0.55
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1962
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.... Read more
Affected Products : cerberus_helpdesk- EPSS Score: %0.41
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1971
Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.... Read more
Affected Products : fusionbb- EPSS Score: %0.44
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1973
Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.... Read more
Affected Products : j2se- EPSS Score: %0.41
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1266
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.... Read more
- EPSS Score: %6.73
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1997
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.... Read more
Affected Products : mcgallery- EPSS Score: %0.40
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2001
Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.... Read more
Affected Products : pafiledb- EPSS Score: %0.54
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1999
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter i... Read more
Affected Products : pafiledb- EPSS Score: %0.41
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1995
Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.... Read more
Affected Products : bitrix_site_manager- EPSS Score: %0.40
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2041
Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).... Read more
Affected Products : virobot_linux_server- EPSS Score: %10.31
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2000
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query ... Read more
Affected Products : pafiledb- EPSS Score: %0.64
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1306
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."... Read more
- EPSS Score: %16.06
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1996
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.... Read more
Affected Products : bitrix_site_manager- EPSS Score: %0.68
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025