Latest CVE Feed
-
7.5
HIGHCVE-2005-1821
PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.... Read more
Affected Products : powerdownload- EPSS Score: %2.93
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1834
SQL injection vulnerability in login.asp in NEXTWEB (i)Site allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.... Read more
Affected Products : nextweb_\(i\)site- EPSS Score: %1.78
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1812
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet.... Read more
Affected Products : tftp_server_2000- EPSS Score: %82.15
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1816
Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen.... Read more
Affected Products : invision_board- EPSS Score: %0.06
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-1794
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.... Read more
- EPSS Score: %9.69
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0356
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the h... Read more
Affected Products : windows_2000 windows_2003_server windows_xp freebsd openbsd emergency_responder content_services_switch_11500 aironet_ap1200 secure_access_control_server tmos +66 more products- EPSS Score: %86.02
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1770
Buffer overflow in the Aavmker4 device driver in Avast! Antivirus 4.6 and possibly other versions allows local users to cause a denial of service (system crash) and possibly execute arbitrary code via certain signals combined with crafted input.... Read more
Affected Products : avast_antivirus- EPSS Score: %0.06
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1781
Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).... Read more
- EPSS Score: %3.27
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1776
Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C'Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.... Read more
Affected Products : cnedra- EPSS Score: %4.76
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1833
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to calendar.php, (2) idsql parameter to online.php, (3) usersearch parameter to memberlist.php, (4... Read more
Affected Products : mybulletinboard- EPSS Score: %1.04
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1780
SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.... Read more
Affected Products : active_news_manager- EPSS Score: %0.58
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1779
SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.... Read more
Affected Products : maxwebportal- EPSS Score: %0.26
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1907
The ISA Firewall service in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service (Wspsrv.exe crash) via a large amount of SecureNAT network traffic.... Read more
Affected Products : isa_server- EPSS Score: %25.48
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1778
Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.... Read more
Affected Products : postnuke- EPSS Score: %0.41
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1866
Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter.... Read more
Affected Products : calendarix_advanced- EPSS Score: %0.43
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1783
BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the result... Read more
Affected Products : bookreview- EPSS Score: %0.46
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1773
Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be SPLIT in the future when more precise technical details become available.... Read more
Affected Products : listserv- EPSS Score: %1.98
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1796
Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code.... Read more
- EPSS Score: %7.88
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1777
SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.... Read more
Affected Products : postnuke- EPSS Score: %0.35
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1771
Unknown vulnerability in HP-UX trusted systems B.11.00 through B.11.23 allows remote attackers to gain unauthorized access, possibly involving remshd and/or telnet -t.... Read more
Affected Products : hp-ux- EPSS Score: %0.76
- Published: May. 31, 2005
- Modified: Apr. 03, 2025