Latest CVE Feed
-
7.5
HIGHCVE-2005-2701
Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.... Read more
- Published: Sep. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2705
Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.... Read more
- Published: Sep. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2704
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.... Read more
- Published: Sep. 23, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2706
Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.... Read more
- Published: Sep. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2702
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.... Read more
- Published: Sep. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2703
Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and... Read more
- Published: Sep. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3044
Multiple vulnerabilities in Linux kernel before 2.6.13.2 allow local users to cause a denial of service (kernel OOPS from null dereference) via (1) fput in a 32-bit ioctl on 64-bit x86 systems or (2) sockfd_put in the 32-bit routing_ioctl function on 64-b... Read more
Affected Products : linux_kernel- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3039
SQL injection vulnerability in infopage.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idPage parameter.... Read more
Affected Products : mall23- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3031
Buffer overflow in vxFtpSrv 0.9.7 allows remote attackers to execute arbitrary code via a long USER name.... Read more
Affected Products : vxftpsrv- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3038
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."... Read more
Affected Products : hosting_controller- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3035
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110.... Read more
Affected Products : driverstudio- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3034
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session.... Read more
Affected Products : driverstudio- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3032
Buffer overflow in vxTftpSrv 1.7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a TFTP request with a long filename argument.... Read more
Affected Products : vxtftpsrv- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3043
SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter.... Read more
Affected Products : mall23- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3033
Stack-based buffer overflow in vxWeb 1.1.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.... Read more
Affected Products : vxweb- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-3036
File Transfer Anywhere 3.01 stores sensitive password information in plaintext in the PASS value in the "File Transfer Anywhere" registry key, which allows local users to gain privileges.... Read more
Affected Products : file_transfer_anywhere- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3042
miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharacters (line feed or carriage return).... Read more
- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3040
Directory traversal vulnerability in the web interface (ISALogin.dll) for TAC Vista 4.0, and possibly other versions before 4.3, allows remote attackers to read arbitrary files via ".." sequences in the Template parameter.... Read more
Affected Products : vista- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3037
Cross-site scripting (XSS) vulnerability in Handy Address Book Server 1.1 allows remote attackers to inject arbitrary web script or HTML via the SEARCHTEXT parameter in a demos URL.... Read more
Affected Products : handy_address_book_server- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3041
Unspecified "drag-and-drop vulnerability" in Opera Web Browser before 8.50 on Windows allows "unintentional file uploads."... Read more
Affected Products : opera_browser- Published: Sep. 22, 2005
- Modified: Apr. 03, 2025