Latest CVE Feed
-
5.0
MEDIUMCVE-2005-1603
NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.... Read more
Affected Products : remote_file_manager- EPSS Score: %4.31
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1609
Unknown vulnerability in Sun StorEdge 6130 Arrays (SE6130) with serial numbers between 0451AWF00G and 0513AWF00J allows local users and remote attackers to delete data.... Read more
Affected Products : storedge_6130_arrays- EPSS Score: %4.79
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1600
A "mathematical flaw" in the implementation of the El Gamal signature algorithm for LibTomCrypt 1.0 to 1.0.2 allows attackers to generate valid signatures without having the private key.... Read more
Affected Products : libtomcrypt- EPSS Score: %0.70
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1616
viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to obtain sensitive information via an invalid (1) id or possibly (2) postorder parameter, which reveals the path in an error message when a file can not be opened.... Read more
Affected Products : ultimate_php_board- EPSS Score: %0.64
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1610
Cross-site scripting (XSS) vulnerability in security.php for Tru-Zone NukeET 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via a base64 encoded Codigo parameter.... Read more
Affected Products : nukeet- EPSS Score: %1.47
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1596
index.php in Fusion SBX 1.2 and earlier does not properly use the extract function, which allows remote attackers to bypass authentication by setting the is_logged parameter or execute arbitrary code via the maxname2 parameter.... Read more
Affected Products : sbx- EPSS Score: %5.24
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1606
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.... Read more
Affected Products : h-sphere_winbox- EPSS Score: %0.33
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1248
Buffer overflow in Apple iTunes before 4.8 allows remote attackers to execute arbitrary code via a crafted MPEG4 file.... Read more
Affected Products : itunes- EPSS Score: %6.28
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1614
Cross-site scripting (XSS) vulnerability in viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the postorder parameter.... Read more
Affected Products : ultimate_php_board- EPSS Score: %0.52
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1591
Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.... Read more
- EPSS Score: %0.66
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1367
Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root.... Read more
Affected Products : pico_server- EPSS Score: %0.42
- Published: May. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1547
Heap-based buffer overflow in the demo version of Bakbone Netvault, and possibly other versions, allows remote attackers to execute arbitrary commands via a large packet to port 20031.... Read more
Affected Products : netvault- EPSS Score: %4.76
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1584
Cross-site scripting (XSS) vulnerability in index.php for Quick.Forum 2.1.6 allows remote attackers to inject arbitrary web script or HTML via the topic field in a NewTopic action.... Read more
Affected Products : quick.forum- EPSS Score: %0.44
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1574
Windows Media Player 9 and 10, in certain cases, allows content protected by Windows Media Digital Rights Management (WMDRM) to redirect the user to a web site to obtain a license, even when the "Acquire licenses automatically for protected content" setti... Read more
- EPSS Score: %4.08
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1566
Acrowave AAP-3100AR wireless router allows remote attackers to bypass authentication by pressing CTRL-C at the username or password prompt in a telnet session, which causes the shell to crash and restart, then leave the user in the new shell.... Read more
Affected Products : wlan_ap_\+_adsl_router- EPSS Score: %0.62
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1577
APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.... Read more
Affected Products : classmaster- EPSS Score: %0.66
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1544
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.... Read more
Affected Products : libtiff- EPSS Score: %15.65
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1546
Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.... Read more
Affected Products : ht_editor- EPSS Score: %2.91
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1571
Multiple directory traversal vulnerabilities in ShowOff! 1.5.4 allow remote attackers to read arbitrary files via ".." sequences in arguments to the (1) ShowAlbum, (2) ShowVideo, or (3) ShowGraphic scripts.... Read more
Affected Products : showoff_digital_media_software- EPSS Score: %0.27
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1581
Cross-site scripting (XSS) vulnerability in Bug Report 1.0 allows remote attackers to inject arbitrary web script or HTML via various fields to bug_report.php, which are not filtered or quoted when processed by bug_list.php or admin/index.php.... Read more
Affected Products : bug_report- EPSS Score: %0.30
- Published: May. 14, 2005
- Modified: Apr. 03, 2025