Latest CVE Feed
-
4.6
MEDIUMCVE-2005-1636
mysql_install_db in MySQL 4.1.x before 4.1.12 and 5.x up to 5.0.4 creates the mysql_install_db.X file with a predictable filename and insecure permissions, which allows local users to execute arbitrary SQL commands by modifying the file's contents.... Read more
- EPSS Score: %0.02
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1641
mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allows IRC users to cause a denial of service.... Read more
Affected Products : ignitionserver- EPSS Score: %0.03
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1634
Multiple cross-site scripting (XSS) vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) anzahl_beitraege parameter to jgs_portal.php, (2) year parameter to jgs_portal_statistik.p... Read more
Affected Products : jgs-portal- EPSS Score: %0.30
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1628
apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter.... Read more
Affected Products : webapp- EPSS Score: %16.90
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1631
booby.php in Booby 1.0.0 and earlier allows remote attackers to view private bookmarks by guessing item IDs.... Read more
Affected Products : booby- EPSS Score: %0.40
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1643
The ZCom_BitStream::Deserialize function in Zoidcom 1.0 beta 4 and earlier allows remote attackers to cause a denial of service via a crafted UDP packet with a large size value, which causes a memory allocation error or an out-of-bounds read.... Read more
Affected Products : zoidcom- EPSS Score: %0.54
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1642
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.... Read more
Affected Products : burning_board- EPSS Score: %0.51
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1640
mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel access entries, which allows remote attackers to bypass i... Read more
Affected Products : ignitionserver- EPSS Score: %0.17
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1633
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parame... Read more
Affected Products : jgs-portal- EPSS Score: %0.31
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1626
Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code.... Read more
Affected Products : pico_server- EPSS Score: %1.18
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1629
SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.... Read more
Affected Products : photopost_php_pro- EPSS Score: %0.29
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1264
Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1... Read more
- EPSS Score: %0.05
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1307
The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts f... Read more
- EPSS Score: %0.67
- Published: May. 17, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1367
Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root.... Read more
Affected Products : pico_server- EPSS Score: %0.42
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1605
Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestbook.GuestBookServ in Standalone Site Studio or (2) E-Guest_sign.pl in Integra... Read more
Affected Products : sitestudio- EPSS Score: %2.53
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1365
Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences.... Read more
Affected Products : pico_server- EPSS Score: %7.34
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1600
A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows attackers to generate valid signatures without having the private key.... Read more
Affected Products : libtomcrypt- EPSS Score: %0.70
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1603
NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.... Read more
Affected Products : remote_file_manager- EPSS Score: %4.31
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1609
Unknown vulnerability in Sun StorEdge 6130 Arrays (SE6130) with serial numbers between 0451AWF00G and 0513AWF00J allows local users and remote attackers to delete data.... Read more
Affected Products : storedge_6130_arrays- EPSS Score: %4.79
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1598
SQL injection vulnerability in Invision Power Board (IPB) 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via a crafted cookie password hash (pass_hash) that modifies the internal $pid variable.... Read more
- EPSS Score: %7.78
- Published: May. 16, 2005
- Modified: Apr. 03, 2025