Latest CVE Feed
-
5.0
MEDIUMCVE-2005-2648
Directory traversal vulnerability in index.php in W-Agora 4.2.0 and earlier allows remote attackers to read arbitrary files via the site parameter.... Read more
Affected Products : w-agora- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2642
Buffer overflow in the mutt_decode_xbit function in Handler.c for Mutt 1.5.10 allows remote attackers to execute arbitrary code, possibly due to interactions with libiconv or gettext.... Read more
Affected Products : mutt- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2665
Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote attackers to execute arbitrary code via an e-mail message with a long Expires header.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2650
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.... Read more
Affected Products : emefa_guestbook- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2681
Unspecified vulnerability in the command line processing (CLI) logic in Cisco Intrusion Prevention System 5.0(1) and 5.0(2) allows local users with OPERATOR or VIEWER privileges to gain additional privileges via unknown vectors.... Read more
Affected Products : ips_sensor_software- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2682
aspell_setup.php in the SpellChecker plugin in DTLink AreaEdit before 0.4.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the dictionary parameter (aka the lang variable).... Read more
Affected Products : areaedit- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2664
Whisper 32 1.16, and possibly earlier versions, stores passwords in plaintext in memory, which allows local users to obtain the password using a debugger or another mechanism to read process memory.... Read more
Affected Products : whisper32- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2678
Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-0359
The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2491
Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which lea... Read more
Affected Products : pcre- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2684
nquser.php in Virtual Edge Netquery 3.11 allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter to a dig query.... Read more
Affected Products : netquery- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2499
slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.... Read more
Affected Products : slocate- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2640
Behavioral discrepancy information leak in Juniper Netscreen VPN running ScreenOS 5.2.0 and earlier, when using IKE with pre-shared key authentication, allows remote attackers to enumerate valid usernames via an IKE Aggressive Mode packet, which generates... Read more
Affected Products : netscreen_screenos screenos instant_virtual_extranet ns-10 ns-100 ns-204 ns-500 ns-50ns25 netscreen-5gt netscreen-idp +7 more products- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2638
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchR... Read more
Affected Products : phpfreenews- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2634
Buffer overflow in the Log-SCR function in the "Log to Screen" feature in WinFtp Server 1.6.8 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long request.... Read more
Affected Products : winftp_server- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2679
Buffer overflow in Sysinternals Process Explorer 9.23, and other versions before 9.25, allows local users to execute arbitrary code via a long CompanyName field in the VersionInfo information in a running process.... Read more
Affected Products : process_explorer- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2670
Directory traversal vulnerability in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall allows remote attackers to overwrite arbitrary files via ".." sequences in filenames contained in (1) ACE, (2) ARJ... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2677
ACNews stores the database in a file under the web document root with a db.inc extension and insufficient access control, which allows remote attackers to obtain sensitive information such as the full pathname of the server.... Read more
Affected Products : acnews- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-2666
SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user's account to generate a lis... Read more
Affected Products : openssh- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2668
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025