Latest CVE Feed
-
7.5
HIGHCVE-2005-1946
Multiple SQL injection vulnerabilities in Invision Blog before 1.1.2 Final allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to an editentry, replyentry, or editcomment action, or (2) the mid parameter to an aboutme action... Read more
Affected Products : invision_community_blog- EPSS Score: %0.65
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1945
Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data.... Read more
Affected Products : invision_community_blog- EPSS Score: %0.44
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1886
Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.... Read more
Affected Products : yapig- EPSS Score: %1.65
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1873
Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command with a long string or (2) a globbing ("*") character follow... Read more
Affected Products : crob_ftp- EPSS Score: %5.39
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1891
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.... Read more
- EPSS Score: %1.41
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1887
Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.... Read more
Affected Products : solaris- EPSS Score: %0.08
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1763
Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.... Read more
- EPSS Score: %0.04
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1947
Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.... Read more
Affected Products : gallery- EPSS Score: %0.97
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1864
PHP remote file inclusion vulnerability in cal_admintop.php in Calendarix Advanced 1.5 allows remote attackers to execute arbitrary PHP code via the calpath parameter.... Read more
Affected Products : calendarix_advanced- EPSS Score: %0.38
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1944
xmysqladmin 1.0 and earlier allows local users to delete arbitrary files via a symlink attack on a database backup file in /tmp.... Read more
Affected Products : xmysqladmin- EPSS Score: %0.07
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1895
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.... Read more
Affected Products : flatnuke- EPSS Score: %3.86
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1948
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.... Read more
Affected Products : invision_gallery- EPSS Score: %0.36
- Published: Jun. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1758
Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.... Read more
Affected Products : netmail- EPSS Score: %7.38
- Published: Jun. 08, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1728
MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials.... Read more
Affected Products : mac_os_x- EPSS Score: %0.06
- Published: Jun. 08, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1723
LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identifier (UTI) is not created when the type is added to the database of unsafe types, which could allow attacke... Read more
Affected Products : mac_os_x_server- EPSS Score: %0.47
- Published: Jun. 08, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1724
NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restrictions.... Read more
Affected Products : mac_os_x_server- EPSS Score: %0.31
- Published: Jun. 08, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2005-1727
Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via "file race conditions."... Read more
Affected Products : mac_os_x_server- EPSS Score: %0.05
- Published: Jun. 08, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1757
Buffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.... Read more
Affected Products : netmail- EPSS Score: %2.04
- Published: Jun. 08, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1943
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.... Read more
Affected Products : loki_download_manager_catgory_version- EPSS Score: %0.57
- Published: Jun. 08, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1968
Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp.... Read more
Affected Products : productcart- EPSS Score: %0.33
- Published: Jun. 08, 2005
- Modified: Apr. 03, 2025