Latest CVE Feed
-
2.6
LOWCVE-2005-1778
Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.... Read more
Affected Products : postnuke- EPSS Score: %0.41
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1779
SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.... Read more
Affected Products : maxwebportal- EPSS Score: %0.26
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1773
Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be SPLIT in the future when more precise technical details become available.... Read more
Affected Products : listserv- EPSS Score: %1.98
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1799
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
- EPSS Score: %0.30
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0356
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the h... Read more
Affected Products : windows_2000 windows_2003_server windows_xp freebsd openbsd emergency_responder content_services_switch_11500 aironet_ap1200 secure_access_control_server tmos +66 more products- EPSS Score: %86.02
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1808
Firefly Studios Stronghold 2 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large size value for the nickname, which causes a memory allocation failure and generates an exception.... Read more
Affected Products : stronghold_2- EPSS Score: %0.89
- Published: May. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1803
Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, or (2) powerpack_f.php, (3) the sitename parameter to sd... Read more
Affected Products : net_portal_dynamic_system- EPSS Score: %0.35
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1789
SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.... Read more
Affected Products : shopping_cart- EPSS Score: %0.45
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1830
The DbgMsg.sys driver in Compuware SoftICE DriverStudio 3.1 and 3.2 allows remote attackers to cause a denial of service (application crash) via an invalid Debug Message pointer.... Read more
Affected Products : softice_driverstudio- EPSS Score: %0.89
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1798
Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.... Read more
Affected Products : monitoring_software- EPSS Score: %0.24
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1804
Multiple SQL injection vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) terme parameter in the glossaire module (glossaire.php) or (2) query parameter to links.php.... Read more
Affected Products : net_portal_dynamic_system- EPSS Score: %0.33
- Published: May. 29, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1791
Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address. NOTE: if there is not an exploit scenar... Read more
Affected Products : ie- EPSS Score: %9.40
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1807
The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field.... Read more
Affected Products : phpmailer- EPSS Score: %15.35
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1800
Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to index.php.... Read more
Affected Products : clamav- EPSS Score: %0.37
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1829
Microsoft Internet Explorer 6 SP2 allows remote attackers to cause a denial of service (infinite loop and application crash) via two embedded files that call each other.... Read more
Affected Products : internet_explorer- EPSS Score: %8.46
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1805
SQL injection vulnerability in login.asp in an unknown product by Online Solutions for Educators (OS4E) allows remote attackers to execute arbitrary SQL commands via the password.... Read more
Affected Products : online_solutions_for_educators- EPSS Score: %0.36
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1806
Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format strings in the URL.... Read more
Affected Products : peercast- EPSS Score: %18.25
- Published: May. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1795
The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent ... Read more
Affected Products : clamav- EPSS Score: %2.17
- Published: May. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1784
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.... Read more
Affected Products : hosting_controller- EPSS Score: %0.44
- Published: May. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1787
setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.... Read more
Affected Products : phpstat- EPSS Score: %6.81
- Published: May. 27, 2005
- Modified: Apr. 03, 2025