Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3566
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) hac... Read more
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3577
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.... Read more
Affected Products : walla_telesite- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3553
Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in conjunction with the login/userinfo.php path and (2) the session parameter (aka the P... Read more
Affected Products : phpkit- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3571
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when ... Read more
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3559
Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access WAV files via a .. (dot dot) in the folder parameter.... Read more
Affected Products : asterisk- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3573
Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to cause a denial of service (application crash).... Read more
Affected Products : mailman- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2659
Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.... Read more
Affected Products : chm_lib- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3344
The default installation of Horde 3.0.4 contains an administrative account with a blank password, which allows remote attackers to gain access.... Read more
Affected Products : horde- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3585
SQL injection vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the forum parameter.... Read more
Affected Products : phpwebthings- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2005-3567
slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and modify and delete directory data via unknown attack vectors.... Read more
Affected Products : tivoli_directory_server- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3556
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) t... Read more
Affected Products : phplist- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3580
QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.... Read more
Affected Products : qdbm- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3587
Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.... Read more
Affected Products : clamav- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3591
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFuncti... Read more
Affected Products : flash_player- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3595
By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.... Read more
Affected Products : windows_xp- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3565
Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.... Read more
Affected Products : hp-ux- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3583
(1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font o... Read more
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3552
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, ... Read more
Affected Products : phpkit- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3550
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.... Read more
Affected Products : toendacms- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-3543
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.... Read more
Affected Products : phorum- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025