Latest CVE Feed
-
7.5
HIGHCVE-2005-3075
SQL injection vulnerability in Zengaia before 0.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : zengaia- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3061
Multiple stack-based buffer overflows in PowerArchiver 8.10 through 9.5 Beta 4 and Beta 5 allow remote attackers to execute arbitrary code via a long filename in a (1) ACE or (2) ARJ archive.... Read more
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3064
MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or delete the message of the day (motd.txt).... Read more
Affected Products : multitheftauto- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3065
MultiTheftAuto 0.5 patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted command 40 that causes a -1 length to be used and triggers an out-of-bounds read.... Read more
Affected Products : multitheftauto- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3067
Cross-site scripting (XSS) vulnerability in perldiver.cgi in PerlDiver 2.x allows remote attackers to inject arbitrary web script or HTML via the module parameter.... Read more
Affected Products : perldiver- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3072
SQL injection vulnerability in pages/forum/submit.html in Interchange 4.9.3 up to 5.2.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : interchange- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3074
SQL injection vulnerability in rsyslogd in RSyslog before 1.0.1 and before 1.10.1 allows remote attackers to execute arbitrary SQL commands via crafted syslog messages.... Read more
Affected Products : rsyslogd- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3071
Unspecified vulnerability in Unix File System (UFS) on Solaris 8 and 9, when logging is enabled, allows local users to cause a denial of service ("soft hang") via certain write operations to UFS.... Read more
- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3073
Unspecified vulnerability in Interchange 5.0.1 allows attackers 4.9.3, 5.0 before 5.0.2, and 5.2, when a catalog has been created using the (1) "mike", (2) "standard", or (3) "foundation" demo, allows attackers to inject Interchange Tag Language (ITL) ele... Read more
Affected Products : interchange- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3068
Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit."... Read more
Affected Products : eric_integrated_development_environment- Published: Sep. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3054
fopen_wrappers.c in PHP 4.4.0, and possibly other versions, does not properly restrict access to other directories when the open_basedir directive includes a trailing slash, which allows PHP scripts in one directory to access files in other directories wh... Read more
Affected Products : php- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3059
Multiple unspecified vulnerabilities in Opera 8.50 on Linux and Windows have unknown impact and attack vectors, related to (1) " handling of must-revalidate cache directive for HTTPS pages" or (2) a "display issue with cookie comment encoding."... Read more
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3055
Linux kernel 2.6.8 to 2.6.14-rc2 allows local users to cause a denial of service (kernel OOPS) via a userspace process that issues a USB Request Block (URB) to a USB device and terminates before the URB is finished, which leads to a stale pointer referenc... Read more
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3053
The sys_set_mempolicy function in mempolicy.c in Linux kernel 2.6.x allows local users to cause a denial of service (kernel BUG()) via a negative first argument.... Read more
- Published: Sep. 26, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-3048
Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the LANGCODE parameter, which also allows direct code injection via the User Agent field ... Read more
Affected Products : phpmyfaq- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3047
Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFaq 1.5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PMF_CONF[version] parameter to footer.php or (2) PMF_LANG[metaLanguage] to header.php.... Read more
Affected Products : phpmyfaq- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3049
PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct request to the data/tracking[DATE] file.... Read more
Affected Products : phpmyfaq- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3045
SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitrary SQL commands via the phrase field.... Read more
Affected Products : my_little_forum- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-3046
SQL injection vulnerability in password.php in PhpMyFaq 1.5.1 allows remote attackers to modify SQL queries and gain administrator privileges via the user field.... Read more
Affected Products : phpmyfaq- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3050
PhpMyFaq 1.5.1 allows remote attackers to obtain sensitive information via a LANGCODE parameter that does not exist, which reveals the path in an error message.... Read more
Affected Products : phpmyfaq- Published: Sep. 24, 2005
- Modified: Apr. 03, 2025