Latest CVE Feed
-
7.5
HIGHCVE-2005-2035
SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.... Read more
Affected Products : cool_cafe_chat- EPSS Score: %0.64
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2042
Cross-site scripting (XSS) vulnerability in ajax-spell before 1.8 allows remote attackers to inject arbitrary web script or HTML via onmouseover or other events in HTML tags.... Read more
Affected Products : ajax-spell- EPSS Score: %0.38
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2027
Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 does not properly restrict certain debugging commands to the ADMIN account, which could allow attackers to obtain sensitive information or modify the registry.... Read more
Affected Products : vertical_horizon-2402s- EPSS Score: %0.30
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2031
Multiple SQL injection vulnerabilities in socialMPN allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter to article.php, (2) uname parameter to user.php, (3) siteid parameter to viewforum.php, (4) username parameter to newtop... Read more
Affected Products : socialmpn- EPSS Score: %0.52
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1965
PHP remote file inclusion vulnerability in siteframe.php for Broadpool Siteframe allows remote attackers to execute arbitrary code via a URL in the LOCAL_PATH parameter.... Read more
Affected Products : siteframe- EPSS Score: %4.42
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1269
Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.... Read more
- EPSS Score: %2.51
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1974
Unspecified vulnerability in Java 2 Platform, Standard Edition (J2SE) 5.0 and 5.0 Update 1 and J2SE 1.4.2 up to 1.4.2_07, as used in multiple products and platforms including (1) HP-UX and (2) APC PowerChute, allows applications to assign permissions to t... Read more
Affected Products : j2se- EPSS Score: %1.02
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2032
Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.... Read more
- EPSS Score: %0.06
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1265
The mmap function in the Linux Kernel 2.6.10 can be used to create memory maps with a start address beyond the end address, which allows local users to cause a denial of service (kernel crash).... Read more
- EPSS Score: %0.06
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1669
Cross-site scripting (XSS) vulnerability in Opera 8.0 Final Build 1095 allows remote attackers to inject arbitrary web script or HTML via "javascript:" URLs when a new window or frame is opened, which allows remote attackers to bypass access restrictions ... Read more
Affected Products : opera_browser- EPSS Score: %0.44
- Published: Jun. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1996
PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.... Read more
Affected Products : bitrix_site_manager- EPSS Score: %0.68
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1306
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."... Read more
- EPSS Score: %16.06
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2041
Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).... Read more
Affected Products : virobot_linux_server- EPSS Score: %10.31
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1266
Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.... Read more
- EPSS Score: %6.73
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2002
SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.... Read more
Affected Products : mambo- EPSS Score: %1.34
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2000
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query ... Read more
Affected Products : pafiledb- EPSS Score: %0.64
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1999
Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter i... Read more
Affected Products : pafiledb- EPSS Score: %0.41
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2001
Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.... Read more
Affected Products : pafiledb- EPSS Score: %0.54
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1995
Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.... Read more
Affected Products : bitrix_site_manager- EPSS Score: %0.40
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1997
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.... Read more
Affected Products : mcgallery- EPSS Score: %0.40
- Published: Jun. 15, 2005
- Modified: Apr. 03, 2025