Latest CVE Feed
-
5.0
MEDIUMCVE-2005-1252
Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string argume... Read more
- EPSS Score: %0.33
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1249
The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop.... Read more
Affected Products : ipswitch_collaboration_suite- EPSS Score: %1.13
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1152
popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.... Read more
- EPSS Score: %0.07
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1543
Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote attacker... Read more
Affected Products : zenworks zenworks_desktops zenworks_servers zenworks_remote_management zenworks_server_management- EPSS Score: %80.37
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2005-1751
Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.... Read more
Affected Products : shtool- EPSS Score: %0.08
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1151
qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.... Read more
- EPSS Score: %0.06
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1750
SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : newsletterez- EPSS Score: %0.60
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1255
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a lon... Read more
- EPSS Score: %6.30
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1256
Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a ... Read more
- EPSS Score: %81.51
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1786
SQL injection vulnerability in admin.asp in FunkyASP AD System 1.1 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password parameter.... Read more
Affected Products : funkyasp_ad_system- EPSS Score: %0.60
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1254
Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (crash) via a SELECT command with a large argument.... Read more
Affected Products : imail- EPSS Score: %5.70
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1693
Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve... Read more
- EPSS Score: %5.14
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1746
The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown)... Read more
- EPSS Score: %0.86
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1695
Multiple cross-site scripting (XSS) vulnerabilities in the RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_url parameter to magpie_slashbox.php, or the url parameter to (2) ma... Read more
Affected Products : postnuke- EPSS Score: %0.34
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1705
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.... Read more
Affected Products : gdb- EPSS Score: %0.06
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2005-1744
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly... Read more
Affected Products : weblogic_server- EPSS Score: %0.72
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-1699
Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.... Read more
Affected Products : postnuke- EPSS Score: %0.33
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1737
Multiple unknown vulnerabilities in PROMS 0.11 allow "non-authorized users" to (1) view or modify the project member list or (2) modify the todos list.... Read more
Affected Products : proms- EPSS Score: %0.53
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1714
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : surgemail- EPSS Score: %0.30
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1745
The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password.... Read more
- EPSS Score: %0.54
- Published: May. 24, 2005
- Modified: Apr. 03, 2025