Latest CVE Feed
-
5.0
MEDIUMCVE-2005-1252
Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string argume... Read more
- EPSS Score: %0.33
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1249
The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop.... Read more
Affected Products : ipswitch_collaboration_suite- EPSS Score: %1.13
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1256
Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a ... Read more
- EPSS Score: %81.51
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1750
SQL injection vulnerability in login.asp in ezdwc NewsletterEz 3.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : newsletterez- EPSS Score: %0.60
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1255
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a lon... Read more
- EPSS Score: %6.30
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1152
popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.... Read more
- EPSS Score: %0.07
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2005-1751
Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.... Read more
Affected Products : shtool- EPSS Score: %0.08
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1739
The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.... Read more
- EPSS Score: %12.13
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1692
Format string vulnerability in gxine 0.4.1 through 0.4.4, and other versions down to 0.3, allows remote attackers to execute arbitrary code via a ram file with a URL whose hostname contains format string specifiers.... Read more
Affected Products : gxine- EPSS Score: %1.96
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1704
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section h... Read more
Affected Products : gdb- EPSS Score: %0.22
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1747
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, ... Read more
- EPSS Score: %2.67
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1698
PostNuke 0.750 and 0.760RC3 allows remote attackers to obtain sensitive information via a direct request to (1) theme.php or (2) Xanthia.php in the Xanthia module, (3) user.php, (4) thelang.php, (5) text.php, (6) html.php, (7) menu.php, (8) finclude.php, ... Read more
Affected Products : postnuke- EPSS Score: %0.32
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-1699
Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.... Read more
Affected Products : postnuke- EPSS Score: %0.33
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1714
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : surgemail- EPSS Score: %0.30
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1741
Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.... Read more
Affected Products : halo_combat_evolved- EPSS Score: %8.72
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1749
Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).... Read more
- EPSS Score: %0.83
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1697
The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.... Read more
Affected Products : postnuke- EPSS Score: %0.32
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1707
The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.... Read more
Affected Products : linux_webapp-config- EPSS Score: %0.23
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1712
Unknown vulnerability in Serendipity 0.8, when used with multiple authors, allows unprivileged authors to upload arbitrary media files.... Read more
Affected Products : serendipity- EPSS Score: %0.44
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1713
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.... Read more
Affected Products : serendipity- EPSS Score: %0.35
- Published: May. 24, 2005
- Modified: Apr. 03, 2025