Latest CVE Feed
-
7.2
HIGHCVE-2005-1770
Buffer overflow in the Aavmker4 device driver in Avast! Antivirus 4.6 and possibly other versions allows local users to cause a denial of service (system crash) and possibly execute arbitrary code via certain signals combined with crafted input.... Read more
Affected Products : avast_antivirus- EPSS Score: %0.06
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1833
Multiple SQL injection vulnerabilities in MyBulletinBoard (MyBB) 1.00 RC4 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to calendar.php, (2) idsql parameter to online.php, (3) usersearch parameter to memberlist.php, (4... Read more
Affected Products : mybulletinboard- EPSS Score: %1.04
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1776
Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C'Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.... Read more
Affected Products : cnedra- EPSS Score: %4.76
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1781
Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).... Read more
- EPSS Score: %3.27
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
8.4
HIGHCVE-2005-1831
Sudo 1.6.8p7 on SuSE Linux 9.3, and possibly other Linux distributions, allows local users to gain privileges by using sudo to call su, then entering a blank password and hitting CTRL-C. NOTE: SuSE and multiple third-party researchers have not been able t... Read more
Affected Products : sudo- EPSS Score: %0.11
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1808
Firefly Studios Stronghold 2 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large size value for the nickname, which causes a memory allocation failure and generates an exception.... Read more
Affected Products : stronghold_2- EPSS Score: %0.89
- Published: May. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1803
Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, or (2) powerpack_f.php, (3) the sitename parameter to sd... Read more
Affected Products : net_portal_dynamic_system- EPSS Score: %0.35
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1830
The DbgMsg.sys driver in Compuware SoftICE DriverStudio 3.1 and 3.2 allows remote attackers to cause a denial of service (application crash) via an invalid Debug Message pointer.... Read more
Affected Products : softice_driverstudio- EPSS Score: %0.89
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1798
Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.... Read more
Affected Products : monitoring_software- EPSS Score: %0.24
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1804
Multiple SQL injection vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) terme parameter in the glossaire module (glossaire.php) or (2) query parameter to links.php.... Read more
Affected Products : net_portal_dynamic_system- EPSS Score: %0.33
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1789
SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.... Read more
Affected Products : shopping_cart- EPSS Score: %0.45
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1800
Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to index.php.... Read more
Affected Products : clamav- EPSS Score: %0.37
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1805
SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password.... Read more
Affected Products : online_solutions_for_educators- EPSS Score: %0.36
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1829
Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other.... Read more
Affected Products : internet_explorer- EPSS Score: %8.46
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1807
The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field.... Read more
Affected Products : phpmailer- EPSS Score: %15.35
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1791
Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address. NOTE: if there is not an exploit scenar... Read more
Affected Products : ie- EPSS Score: %9.40
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1806
Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format strings in the URL.... Read more
Affected Products : peercast- EPSS Score: %18.25
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1787
setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.... Read more
Affected Products : phpstat- EPSS Score: %6.81
- Published: May. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1802
Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header.... Read more
- EPSS Score: %0.76
- Published: May. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1795
The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent ... Read more
Affected Products : clamav- EPSS Score: %2.17
- Published: May. 27, 2005
- Modified: Apr. 03, 2025