Latest CVE Feed
-
5.0
MEDIUMCVE-2005-3244
The BER dissector in Ethereal 0.10.3 to 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-3321
chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating a hardlink to a file from a world-writable directory, which can cause the link count to drop to 1 when the file is deleted or replaced, which is then modi... Read more
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3318
Buffer overflow in the _chm_decompress_block function in CHM lib (chmlib) before 0.37, as used in products such as KchmViewer, allows attackers to execute arbitrary code, a different vulnerability than CVE-2005-2930.... Read more
Affected Products : chm_lib- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3317
Multiple stack-based buffer overflows in ZipGenius 5.5.1.468 and 6.0.2.1041, and other versions before 6.0.2.1050, allow remote attackers to execute arbitrary code via (1) a ZIP archive that contains a file with a long filename, which is not properly hand... Read more
Affected Products : zipgenius- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3323
docutils in Zope 2.6, 2.7 before 2.7.8, and 2.8 before 2.8.2 allows remote attackers to include arbitrary files via include directives in RestructuredText functionality.... Read more
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3326
SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.... Read more
Affected Products : mybulletinboard- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3330
The _httpsrequest function in Snoopy 1.2, as used in products such as (1) MagpieRSS, (2) WordPress, (3) Ampache, and (4) Jinzora, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTPS URL to an SSL protected web page, ... Read more
Affected Products : snoopy- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3338
Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users.... Read more
Affected Products : mantis- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3333
SQL injection vulnerability in eBASEweb 3.0 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : ebaseweb- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3332
PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via the match parameter.... Read more
Affected Products : vcard- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3242
Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (crash) via unknown vectors in (1) the IrDA dissector and (2) the SMB dissector when SMB transaction payload reassembly is enabled.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3319
The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or Vi... Read more
Affected Products : php- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3325
Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products... Read more
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3245
Unspecified vulnerability in the ONC RPC dissector in Ethereal 0.10.3 to 0.10.12, when the "Dissect unknown RPC program numbers" option is enabled, allows remote attackers to cause a denial of service (memory consumption).... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3327
Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation protocol, and uses Operational mode without proving identi... Read more
Affected Products : data_ontap- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3322
Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).... Read more
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3337
Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php.... Read more
Affected Products : mantis- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3243
Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-3320
Cross-site scripting (XSS) vulnerability in SiteTurn Domain Manager Pro allows remote attackers to inject arbitrary web script or HTML via the err parameter in the panel script.... Read more
Affected Products : domain_manager_pro- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2338
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in ... Read more
Affected Products : xoops- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025