Latest CVE Feed
-
6.8
MEDIUMCVE-2005-1614
Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter.... Read more
Affected Products : ultimate_php_board- EPSS Score: %0.52
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1248
Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.... Read more
Affected Products : itunes- EPSS Score: %6.28
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1603
NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.... Read more
Affected Products : remote_file_manager- EPSS Score: %4.31
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1599
Cross-site scripting (XSS) vulnerability in Kryloff Technologies Subject Search Server (SSServer) 1.1 allows remote attackers to inject arbitrary web script or HTML via the "Search For" field.... Read more
Affected Products : subject_search_server- EPSS Score: %0.35
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1601
MRO Maximo Self Service 4 and 5 stores certain information under the web document root using file extensions that are not processed by Tomcat, which allows remote attackers to obtain sensitive information via a direct request for the file, such as MXServe... Read more
Affected Products : maximo_self_service- EPSS Score: %0.43
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1606
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.... Read more
Affected Products : h-sphere_winbox- EPSS Score: %0.33
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1596
index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.... Read more
Affected Products : sbx- EPSS Score: %5.24
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1610
Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via a base64 encoded Codigo parameter.... Read more
Affected Products : nukeet- EPSS Score: %1.47
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1617
Willings WebCam and WebCam Lite 2.8 and earlier stores the password in memory in plaintext, which allows local users to gain sensitive information.... Read more
- EPSS Score: %0.06
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1592
Multiple "javascript vulerabilities in BB code" in BirdBlog before 1.3.1 allow remote attackers to inject arbitrary Javascript.... Read more
Affected Products : birdblog- EPSS Score: %0.66
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1607
Cross-site scripting (XSS) vulnerability in shop.cgi in Remote Cart allows remote attackers to inject arbitrary web script or HTML via the (1) merchant or (2) demo parameters.... Read more
Affected Products : remote_cart- EPSS Score: %1.17
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1582
Cross-site scripting (XSS) vulnerability in index.php for 1Two News 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) nom, (2) email, (3) siteweb, or (4) commentaire variables.... Read more
Affected Products : 1two_news- EPSS Score: %0.35
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1569
Cross-site scripting (XSS) vulnerability in DirectTopics 2.1 and 2.2 allows remote attackers to inject arbitrary web script via a javascript: URL in (1) a thread or (2) an IMG tag.... Read more
Affected Products : directtopics- EPSS Score: %0.30
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1587
Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.... Read more
Affected Products : quick.cart- EPSS Score: %0.53
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1550
easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter.... Read more
Affected Products : easy_message_board- EPSS Score: %6.58
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1577
APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.... Read more
Affected Products : classmaster- EPSS Score: %0.66
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1570
forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.... Read more
Affected Products : bttlxeforum- EPSS Score: %0.34
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1544
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.... Read more
Affected Products : libtiff- EPSS Score: %15.65
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1556
Gamespy cd-key validation system allows remote attackers to cause a denial of service (cd-key already in use) by capturing and replaying a cd-key authorization session.... Read more
Affected Products : gamespy_sdk_cd-key_validation_toolkit- EPSS Score: %1.13
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1575
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.... Read more
Affected Products : firefox- EPSS Score: %0.49
- Published: May. 14, 2005
- Modified: Apr. 03, 2025