Latest CVE Feed
-
10.0
HIGHCVE-2005-2286
WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.... Read more
Affected Products : webeoc- EPSS Score: %1.20
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2285
WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Usernames, Passwords, Emergency information, medical information, and system config... Read more
Affected Products : webeoc- EPSS Score: %0.48
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2284
Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors.... Read more
Affected Products : webeoc- EPSS Score: %0.45
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2195
Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulner... Read more
Affected Products : darwin_streaming_server- EPSS Score: %0.76
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1174
MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.... Read more
Affected Products : kerberos_5- EPSS Score: %40.92
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2288
Cross-site scripting (XSS) vulnerability in PHPCounter 7.2 allows remote attackers to inject arbitrary web script or HTML via the EpochPrefix parameter.... Read more
Affected Products : phpcounter- EPSS Score: %0.35
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2287
SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space, possibly triggering a buffer overflow.... Read more
Affected Products : wmailserver- EPSS Score: %79.84
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2283
WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file.... Read more
Affected Products : webeoc- EPSS Score: %0.47
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2005-2293
Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is not deleted after it is used, which allows local users to obtain sensitive information.... Read more
Affected Products : forms_builder- EPSS Score: %0.16
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1175
Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.... Read more
Affected Products : kerberos_5- EPSS Score: %45.40
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2289
PHPCounter 7.2 allows remote attackers to obtain sensitive information via a direct request to prelims.php, which reveals the path in an error message.... Read more
Affected Products : phpcounter- EPSS Score: %0.39
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1914
CenterICQ 4.20.0 and earlier creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack on the gg.token.PID temporary file.... Read more
Affected Products : centericq- EPSS Score: %0.18
- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2277
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.... Read more
Affected Products : affix- EPSS Score: %7.22
- Published: Jul. 15, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-2262
Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascrip... Read more
Affected Products : firefox- EPSS Score: %16.00
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2249
Multiple unknown vulnerabilities in Jinzora 2.0.1 have unknown impact and attack vectors, possibly involving a PHP file inclusion vulnerability.... Read more
Affected Products : jinzora- EPSS Score: %0.46
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2264
Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.... Read more
Affected Products : firefox- EPSS Score: %3.23
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2271
iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."... Read more
Affected Products : icab- EPSS Score: %0.35
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2248
Directory traversal vulnerability in DownloadProtect before 1.0.3 allows remote attackers to read files above the download folder.... Read more
Affected Products : downloadprotect- EPSS Score: %0.24
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2255
Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php.... Read more
Affected Products : phpauction- EPSS Score: %0.26
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2267
Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to... Read more
Affected Products : firefox- EPSS Score: %5.04
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025