Latest CVE Feed
-
2.1
LOWCVE-2005-2977
The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses.... Read more
Affected Products : pam- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3394
Multiple SQL injection vulnerabilities in forum.php in oaboard forum 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) channel parameter in the topics module and (2) topic parameter in the posting module.... Read more
Affected Products : oaboard- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3398
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTT... Read more
- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3388
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.x up to 4.4.0 and 5.x up to 5.0.5 allows remote attackers to inject arbitrary web script or HTML via a crafted URL with a "stacked array assignment."... Read more
Affected Products : php- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3313
The IRC protocol dissector in Ethereal 0.10.13 allows remote attackers to cause a denial of service (infinite loop).... Read more
Affected Products : ethereal- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3315
Multiple SQL injection vulnerabilities in Novell ZENworks Patch Management 6.x before 6.2.2.181 allow remote attackers to execute arbitrary SQL commands via the (1) Direction parameter to computers/default.asp, and the (2) SearchText, (3) StatusFilter, an... Read more
Affected Products : zenworks_patch_management_server- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3123
Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".." and "//" sequences are removed.... Read more
Affected Products : gnump3d- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3379
Multiple interpretation error in Trend Micro (1) PC-Cillin 2005 12.0.1244 with the 7.510.1002 engine and (2) OfficeScan 7.0 with the 7.510.1002 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magi... Read more
- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3384
SQL injection vulnerability in Techno Dreams Guest Book script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.... Read more
Affected Products : techno_dreams_guest_book- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3383
SQL injection vulnerability in Techno Dreams Announcement script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.... Read more
Affected Products : announcement_script- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3372
Multiple interpretation error in eTrust CA 7.0.1.4 with the 11.9.1 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file ... Read more
Affected Products : etrust_antivirus- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3371
Multiple interpretation error in AVG 7 7.0.323 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe typ... Read more
Affected Products : avg_antivirus- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3369
Multiple SQL injection vulnerabilities in the Info-DB module (info_db.php) in Woltlab Burning Board 2.7 and earlier allow remote attackers to execute arbitrary SQL commands and possibly upload files via the (1) fileid and (2) subkatid parameters.... Read more
Affected Products : burning_board- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3370
Multiple interpretation error in ArcaVir 2005 package 2005-06-21 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be tre... Read more
Affected Products : arcavir_2005- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3380
Multiple interpretation error in Panda Titanium 2005 4.02.01 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated... Read more
Affected Products : titanium_2005- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3376
Multiple interpretation error in Kaspersky 5.0.372 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe... Read more
Affected Products : kaspersky_anti-virus- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3381
Multiple interpretation error in Ukrainian National Antivirus (UNA) 1.83.2.16 with kernel 265 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, wh... Read more
Affected Products : una- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3377
Multiple interpretation error in (1) McAfee Internet Security Suite 7.1.5 version 9.1.08 with the 4.4.00 engine and (2) McAfee Corporate 8.0.0 patch 10 with the 4400 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and... Read more
Affected Products : internet_security_suite- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3367
Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field.... Read more
Affected Products : sparkleblog- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3385
SQL injection vulnerability in Techno Dreams Mailing List script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.... Read more
Affected Products : mailing_list- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025