Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2093
Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length h... Read more
Affected Products : application_server- EPSS Score: %2.59
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1931
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.... Read more
Affected Products : goodtech_smtp_server- EPSS Score: %4.01
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2112
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter to edit.php or (2) cid parameter to comment_edit.php.... Read more
Affected Products : xoops- EPSS Score: %0.56
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2111
login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.... Read more
Affected Products : community_link_pro_web_editor- EPSS Score: %2.88
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2110
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an erro... Read more
Affected Products : wordpress- EPSS Score: %1.23
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2113
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via crafted values in an XML file, as demonstrated using the blogger... Read more
Affected Products : xoops- EPSS Score: %0.97
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2142
Directory traversal vulnerability in Golden FTP Server 2.60 allows remote authenticated attackers to list arbitrary directories via a "\.." (backslash dot dot) in an LS (LIST) command.... Read more
Affected Products : golden_ftp_server- EPSS Score: %0.15
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2069
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sni... Read more
- EPSS Score: %2.84
- Published: Jun. 30, 2005
- Modified: Apr. 03, 2025
-
6.5
MEDIUMCVE-2005-2059
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) addaddress.php, (2) toggleignore.php, (3) removeignore.php, and (4) removeaddress.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to modify settings as another user via ... Read more
Affected Products : ubb.threads- EPSS Score: %0.32
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2058
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month ... Read more
Affected Products : ubb.threads- EPSS Score: %0.58
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2076
HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.... Read more
Affected Products : version_control_repository_manager- EPSS Score: %0.19
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2063
Multiple cross-site scripting (XSS) vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to sendpassword.asp or (2) Keyword field in search.asp.... Read more
Affected Products : activebuyandsell- EPSS Score: %0.30
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-2057
Multiple cross-site scripting (XSS) vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to inject arbitrary web script or HTML via the (1) Searchpage parameter to dosearch.php, (2) Number, (3) what, or (4) page parameter to new... Read more
Affected Products : ubb.threads- EPSS Score: %1.17
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2073
Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.... Read more
Affected Products : db2- EPSS Score: %0.06
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2080
Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.... Read more
Affected Products : backup_exec- EPSS Score: %0.74
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2055
RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via "default settings of earlier Internet Explorer browsers".... Read more
- EPSS Score: %0.34
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2064
Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, ... Read more
Affected Products : asp-nuke- EPSS Score: %4.08
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2061
Infopop UBB.Threads before 6.5.2 Beta allows remote attackers to include arbitrary files via the language parameter in a cookie followed by a null (%00) byte.... Read more
Affected Products : ubb.threads- EPSS Score: %0.38
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2078
BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.... Read more
Affected Products : bisonftp- EPSS Score: %0.61
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2056
The Quantum archive decompressor in Clam AntiVirus (ClamAV) before 0.86.1 allows remote attackers to cause a denial of service (application crash) via a crafted Quantum archive.... Read more
Affected Products : clamav- EPSS Score: %1.10
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025