Latest CVE Feed
-
10.0
HIGHCVE-2005-3444
Multiple unspecified vulnerabilities in the Programmatic Interface in Oracle Database Server from 8i up to 9.2.0.5 have unknown impact and attack vectors, aka Oracle Vuln# DB26.... Read more
Affected Products : database_server- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3431
Absolute path traversal vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to read arbitrary files via a full pathname in the AttachPath field of a mail message under composition.... Read more
Affected Products : mailsite_express- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3442
Multiple unspecified vulnerabilities in Oracle Database Server 8i up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB09 in Export, (2) DB11 in Materialized Views, and (3) DB16 in Security Service.... Read more
Affected Products : database_server- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3439
Multiple unspecified vulnerabilities in Oracle Database Server 10g up to 10.1.0.4.2 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB02, (2) DB03, and (3) DB05 in Change Data Capture; (4) DB07 in Data Pump Export; and (5) DB18, (6) DB19, (7)... Read more
Affected Products : database_server- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3428
Cross-site scripting (XSS) vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to inject arbitrary web script or HTML via a message body.... Read more
Affected Products : mailsite_express- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3433
Buffer overflow in Mirabilis ICQ 2003a allows user-assisted attackers to execute arbitrary code by convincing a user to enter long strings into the First Name and Last Name fields.... Read more
Affected Products : icq- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3437
Unspecified vulnerability in the PL/SQL component in Oracle Database Server 9i up to 10.1.0.4 has unknown impact and attack vectors, aka Oracle Vuln# DB01.... Read more
Affected Products : database_server- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3436
Cross-site scripting (XSS) vulnerability in Nuked-Klan 1.7 allows remote attackers to inject arbitrary web script or HTML via the (1) Search module, (2) certain edit fields in Guestbook, (3) the title in the Forum module, and (4) Textbox.... Read more
Affected Products : nuked-klan- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3443
Unspecified vulnerability in the Spatial component in Oracle Database Server from 9i up to 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# DB17.... Read more
Affected Products : database_server- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3432
MiniGal 2 (MG2) 0.5.1 allows remote attackers to list password protected images via a request to index.php with the list parameter set to * (wildcard) and the page parameter set to all.... Read more
Affected Products : minigal_2- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3409
OpenVPN 2.x before 2.0.4, when running in TCP mode, allows remote attackers to cause a denial of service (segmentation fault) by forcing the accept function call to return an error status, which leads to a null dereference in an exception handler.... Read more
- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3426
Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation.... Read more
Affected Products : content_services_switch_11500- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3427
The Cisco Management Center (MC) for IPS Sensors (IPS MC) 2.1 can omit port field values while generating the Cisco IOS IPS configuration file, wich can cause some signatures to be disabled and makes it easier for attackers to escape detection.... Read more
Affected Products : ciscoworks_management_center_for_ips_sensors- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3423
Multiple SQL injection vulnerabilities in Subdreamer 2.2.1 allow remote attackers to execute arbitrary SQL commands via (1) the loginusername parameter or (2) cookies to (a) subdreamer.php, (b) ipb2.php, (c) phpbb2.php, (d) vbulletin2.php, and (e) vbullet... Read more
Affected Products : subdreamer- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3425
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2005-3424.... Read more
Affected Products : gnump3d- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3424
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425.... Read more
Affected Products : gnump3d- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3422
Cross-site scripting (XSS) vulnerability in error.asp in ASP Fast Forum allows remote attackers to inject arbitrary web script or HTML via the error parameter.... Read more
Affected Products : asp_fast_forum- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3421
estcmd in Hyper Estraier 1.0.1 on Windows systems allows remote attackers to read unauthorized files via a crafted search request for a filename that contains Unicode characters.... Read more
Affected Products : hyper_estraier- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3418
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.17 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) error_msg parameter to usercp_register.php, (2) forward_page parameter to login.php, and (3) list_cat... Read more
Affected Products : phpbb- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3419
SQL injection vulnerability in usercp_register.php in phpBB 2.0.17 allows remote attackers to execute arbitrary SQL commands via the signature_bbcode_uid parameter, which is not properly initialized.... Read more
Affected Products : phpbb- Published: Nov. 01, 2005
- Modified: Apr. 03, 2025