Latest CVE Feed
-
7.2
HIGHCVE-2005-1905
The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later accessed by privileged programs.... Read more
- EPSS Score: %0.15
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1909
The web server control panel in 602LAN SUITE 2004 allows remote attackers to make it more difficult for the administrator to read portions of log files via a "</pre><!-" sequence in an HTTP GET request in the logon, possibly due to a cross-site scripting ... Read more
Affected Products : 602lan_suite- EPSS Score: %0.35
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1950
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.... Read more
Affected Products : webhints- EPSS Score: %11.35
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1873
Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command with a long string or (2) a globbing ("*") character follow... Read more
Affected Products : crob_ftp- EPSS Score: %5.39
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1946
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action... Read more
Affected Products : invision_community_blog- EPSS Score: %0.65
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1945
Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.... Read more
Affected Products : invision_community_blog- EPSS Score: %0.44
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1891
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.... Read more
- EPSS Score: %1.41
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1886
Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.... Read more
Affected Products : yapig- EPSS Score: %1.65
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1882
PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter.... Read more
Affected Products : yapig- EPSS Score: %2.26
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1867
Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges.... Read more
Affected Products : brightmail_antispam- EPSS Score: %1.13
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1878
GIPTables Firewall 1.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the temp.ip.addresses temporary file.... Read more
Affected Products : giptables_firewall- EPSS Score: %0.07
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1897
Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.... Read more
Affected Products : flexcast_audio_video_streaming_server- EPSS Score: %0.39
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1871
Unknown vulnerability in the privilege system in Drupal 4.4.0 through 4.6.0, when public registration is enabled, allows remote attackers to gain privileges, due to an "input check" that "is not implemented properly."... Read more
Affected Products : drupal- EPSS Score: %0.74
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1948
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.... Read more
Affected Products : invision_gallery- EPSS Score: %0.36
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1904
SQL injection vulnerability in login.asp in JiRo's Upload System (JUS) 1 allows remote attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : jiro_upload_system- EPSS Score: %0.50
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1896
Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation path via the image parameter.... Read more
Affected Products : flatnuke- EPSS Score: %0.90
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1895
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.... Read more
Affected Products : flatnuke- EPSS Score: %3.86
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1864
PHP remote file inclusion vulnerability in cal_admintop.php in Calendarix Advanced 1.5 allows remote attackers to execute arbitrary PHP code via the calpath parameter.... Read more
Affected Products : calendarix_advanced- EPSS Score: %0.38
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1944
xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.... Read more
Affected Products : xmysqladmin- EPSS Score: %0.07
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1898
The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.... Read more
Affected Products : phpthumb- EPSS Score: %0.39
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025