Latest CVE Feed
-
7.5
HIGHCVE-2005-2564
Direct static code injection vulnerability in editcss.php in Gravity Board X (GBX) 1.1 allows remote attackers to execute arbitrary PHP code, HTML, and script via the csscontent parameter, which is directly inserted into the gbxfinal.css file.... Read more
Affected Products : gravity_board_x- EPSS Score: %3.15
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2005-2103
Buffer overflow in the AIM and ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an away message with a large number of AIM substitution strings, such as %t or ... Read more
- EPSS Score: %25.85
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2584
The web administration interface in Mentor ADSL-FR4II router running firmware 2.00.0111 does not set a default password, which allows local users to gain access.... Read more
Affected Products : adslfr4ii- EPSS Score: %0.05
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2097
xpdf and kpdf do not properly validate the "loca" table in PDF files, which allows local users to cause a denial of service (disk consumption and hang) via a PDF file with a "broken" loca table, which causes a large temporary file to be created when xpdf ... Read more
- EPSS Score: %0.07
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2585
Mentor ADSL-FR4II router running firmware 2.00.0111 allows remote attackers to cause a denial of service (active TCP connections state table consumption) via a large number of connections, such as a port scan.... Read more
Affected Products : adslfr4ii- EPSS Score: %0.66
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2102
The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.... Read more
- EPSS Score: %1.25
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2583
Mentor ADSL-FR4II router running firmware 2.00.0111 has an undocumented web server running on TCP port 5678, which allows local users to gain access.... Read more
Affected Products : adslfr4ii- EPSS Score: %0.34
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2498
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nes... Read more
- EPSS Score: %4.69
- Published: Aug. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1527
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call... Read more
- EPSS Score: %1.33
- Published: Aug. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2549
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list da... Read more
- EPSS Score: %2.93
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2551
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.... Read more
Affected Products : edirectory- EPSS Score: %71.76
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2547
security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.... Read more
Affected Products : bluez- EPSS Score: %1.14
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2553
The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program... Read more
Affected Products : linux_kernel- EPSS Score: %0.09
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2550
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects... Read more
- EPSS Score: %5.16
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2552
Unknown vulnerability in HP ProLiant DL585 servers running Integrated Lights Out (ILO) firmware before 1.81 allows attackers to access server controls when the server is "powered down."... Read more
Affected Products : proliant_dl585- EPSS Score: %0.64
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2554
The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.... Read more
Affected Products : epolicy_orchestrator_agent- EPSS Score: %0.05
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2548
vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snm... Read more
Affected Products : linux_kernel- EPSS Score: %1.84
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2543
Directory traversal vulnerability in wce.download.php in Comdev eCommerce 3.0 allows remote attackers to download arbitrary files via a .. (dot dot) in the download parameter.... Read more
Affected Products : comdev_ecommerce- EPSS Score: %3.05
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2544
PHP remote file inclusion vulnerability in config.php in Comdev eCommerce 3.0 allows remote attackers to execute arbitrary PHP code via the path[docroot] parameter.... Read more
Affected Products : comdev_ecommerce- EPSS Score: %0.48
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1984
Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.... Read more
- EPSS Score: %31.43
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025