Latest CVE Feed
-
2.1
LOWCVE-2005-1903
Buffer overflow in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to execute arbitrary code via a long CREATE command.... Read more
Affected Products : spa-pro_mail_atsolomon- EPSS Score: %3.29
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1906
SQL injection vulnerability in login.asp in livingmailing 1.3 allows remote attackers to execute arbitrary SQL commands via the password. NOTE: there is little public information about this product and its vendor, and the original researcher announcement ... Read more
Affected Products : livingmailing- EPSS Score: %0.49
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1840
Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.... Read more
Affected Products : phpcms- EPSS Score: %1.14
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-1794
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.... Read more
- EPSS Score: %9.69
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1788
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.... Read more
Affected Products : hosting_controller- EPSS Score: %0.29
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1835
NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb.... Read more
Affected Products : nextweb_\(i\)site- EPSS Score: %0.68
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1792
Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache.... Read more
Affected Products : windows_xp- EPSS Score: %13.08
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1793
User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.... Read more
Affected Products : windows_98se- EPSS Score: %8.92
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1814
Stack-based buffer overflow in PicoWebServer 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URL.... Read more
Affected Products : picowebserver- EPSS Score: %2.41
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1818
Multiple SQL injection vulnerabilities in NewLife Blogger before 3.3.1 allow remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : newlife_blogger- EPSS Score: %0.49
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1836
NEXTWEB (i)Site allows remote attackers to cause a denial of service (error 500) via a crafted HTTP request, possibly involving wildcard requests for .jsp files.... Read more
Affected Products : nextweb_\(i\)site- EPSS Score: %2.94
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1810
SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.... Read more
Affected Products : wordpress- EPSS Score: %1.64
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1816
Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen.... Read more
Affected Products : invision_board- EPSS Score: %0.06
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1812
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet.... Read more
Affected Products : tftp_server_2000- EPSS Score: %82.15
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1834
SQL injection vulnerability in login.asp in NEXTWEB (i)Site allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.... Read more
Affected Products : nextweb_\(i\)site- EPSS Score: %1.78
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1809
Sony Ericsson P900 Beamer allows remote attackers to cause a denial of service (panic) via an obexftp session with a long filename in an OBEX File Transfer or OBEX Object Push.... Read more
- EPSS Score: %1.04
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1817
Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.... Read more
Affected Products : invision_board- EPSS Score: %2.95
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1811
Cross-site scripting (XSS) vulnerability in usercp.php for MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via the website field in a user profile.... Read more
Affected Products : mybulletinboard- EPSS Score: %0.41
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-1813
Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (2) "..\" (dot dot backslash) sequences.... Read more
Affected Products : tftp_server_2000- EPSS Score: %0.42
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1821
PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.... Read more
Affected Products : powerdownload- EPSS Score: %2.93
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025