Latest CVE Feed
-
2.1
LOWCVE-2005-1858
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a short byte count to a read request, which may allow local users to obtain sensitive information.... Read more
Affected Products : fuse- EPSS Score: %0.18
- Published: Jun. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1824
The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.... Read more
Affected Products : mailutils- EPSS Score: %1.24
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1839
Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.asp or (2) print.asp or (3) edit parameter to register.asp.... Read more
Affected Products : liberum_help_desk- EPSS Score: %0.58
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1875
Multiple SQL injection vulnerabilities in list.php in Exhibit Engine (EE) 1.22 allow remote attackers to execute arbitrary SQL commands via the (1) search_row, (2) sort_row, (3) order or (4) perpage parameter.... Read more
Affected Products : exhibit_engine- EPSS Score: %0.73
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1906
SQL injection vulnerability in login.asp in livingmailing 1.3 allows remote attackers to execute arbitrary SQL commands via the password. NOTE: there is little public information about this product and its vendor, and the original researcher announcement ... Read more
Affected Products : livingmailing- EPSS Score: %0.49
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1903
Buffer overflow in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to execute arbitrary code via a long CREATE command.... Read more
Affected Products : spa-pro_mail_atsolomon- EPSS Score: %3.29
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1838
Multiple cross-site scripting vulnerabilities in castnewPost.asp in Liberum Help Desk 0.97.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Email, (2) Title, or (3) Description fields.... Read more
Affected Products : liberum_help_desk- EPSS Score: %0.35
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1840
Directory traversal vulnerability in class.layout_phpcms.php in phpCMS 1.2.x before 1.2.1pl2 allows remote attackers to read or include arbitrary files, as demonstrated using a .. (dot dot) in the language parameter to parser.php.... Read more
Affected Products : phpcms- EPSS Score: %1.14
- Published: Jun. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1810
SQL injection vulnerability in template-functions-category.php in WordPress 1.5.1 allows remote attackers to execute arbitrary SQL commands via the $cat_ID variable, as demonstrated using the cat parameter to index.php.... Read more
Affected Products : wordpress- EPSS Score: %1.64
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1816
Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen.... Read more
Affected Products : invision_board- EPSS Score: %0.06
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1793
User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.... Read more
Affected Products : windows_98se- EPSS Score: %8.92
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1836
NEXTWEB (i)Site allows remote attackers to cause a denial of service (error 500) via a crafted HTTP request, possibly involving wildcard requests for .jsp files.... Read more
Affected Products : nextweb_\(i\)site- EPSS Score: %2.94
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1835
NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb.... Read more
Affected Products : nextweb_\(i\)site- EPSS Score: %0.68
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1818
Multiple SQL injection vulnerabilities in NewLife Blogger before 3.3.1 allow remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : newlife_blogger- EPSS Score: %0.49
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1814
Stack-based buffer overflow in PicoWebServer 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URL.... Read more
Affected Products : picowebserver- EPSS Score: %2.41
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1792
Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache.... Read more
Affected Products : windows_xp- EPSS Score: %13.08
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1837
Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console access to gain privileges.... Read more
Affected Products : fortinet_firewall- EPSS Score: %0.34
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1817
Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.... Read more
Affected Products : invision_board- EPSS Score: %2.95
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1815
Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of dat... Read more
Affected Products : connectivity- EPSS Score: %62.87
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1790
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismat... Read more
Affected Products : internet_explorer- EPSS Score: %84.75
- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025