Latest CVE Feed
-
7.5
HIGHCVE-2005-3074
SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.... Read more
Affected Products : rsyslogd- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3076
Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid, (3) cid, or (4) m parameters to archive.php, or the (5) blogid parameter to blogadmin.php.... Read more
Affected Products : simplog- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3061
Multiple stack-based buffer overflows in PowerArchiver 8.10 through 9.5 Beta 4 and Beta 5 allow remote attackers to execute arbitrary code via a long filename in a (1) ACE or (2) ARJ archive.... Read more
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3075
SQL injection vulnerability in Zengaia before 0.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : zengaia- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-3070
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.... Read more
Affected Products : hylafax- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3064
MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or delete the message of the day (motd.txt).... Read more
Affected Products : multitheftauto- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3062
PHP remote file inclusion vulnerability in index.php in AlstraSoft E-Friends 4.0 allows remote attackers to execute arbitrary PHP code via the mode parameter.... Read more
Affected Products : e-friends- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3069
xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.... Read more
Affected Products : hylafax- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3068
Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit."... Read more
Affected Products : eric_integrated_development_environment- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3063
SQL injection vulnerability in MailGust 1.9 allows remote attackers to execute arbitrary SQL commands via the email field on the password reminder page.... Read more
Affected Products : mailgust- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3066
Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver 1.x allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: this issue was originally disputed by the vendor, but it has since been acknowledged.... Read more
Affected Products : perldiver- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3071
Unspecified vulnerability in Unix File System (UFS) on Solaris 8 and 9, when logging is enabled, allows local users to cause a denial of service ("soft hang") via certain write operations to UFS.... Read more
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3073
Unspecified vulnerability in Interchange 5.0.1 allows attackers 4.9.3, 5.0 before 5.0.2, and 5.2, when a catalog has been created using the (1) "mike", (2) "standard", or (3) "foundation" demo, allows attackers to inject Interchange Tag Language (ITL) ele... Read more
Affected Products : interchange- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3053
The sys_set_mempolicy function in mempolicy.c in Linux kernel 2.6.x allows local users to cause a denial of service (kernel BUG()) via a negative first argument.... Read more
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3059
Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-revalidate cache directive for HTTPS pages" or (2) a "display issue with cookie comment encoding."... Read more
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3055
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer referenc... Read more
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3054
fopen_wrappers.c in PHP 4.4.0, and possibly other versions, does not properly restrict access to other directories when the open_basedir directive includes a trailing slash, which allows PHP scripts in one directory to access files in other directories wh... Read more
Affected Products : php- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3049
PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.... Read more
Affected Products : phpmyfaq- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-3046
SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.... Read more
Affected Products : phpmyfaq- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2005-3051
Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including Turbo Searcher, allows remote attackers to execute arbitrary code via a large ARJ block.... Read more
Affected Products : 7-zip- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025