Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3556
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) listname parameter in (a) admin/editlist.php, (2) title parameter in (b) admin/spageedit.php, (3) t... Read more
Affected Products : phplist- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3580
QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.... Read more
Affected Products : qdbm- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3587
Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors.... Read more
Affected Products : clamav- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3591
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via parameters to the ActionDefineFuncti... Read more
Affected Products : flash_player- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3595
By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.... Read more
Affected Products : windows_xp- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3565
Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.... Read more
Affected Products : hp-ux- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3583
(1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font o... Read more
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3552
Multiple cross-site scripting (XSS) vulnerabilities in PHPKIT 1.6.1 R2 and earlier allow remote attackers to inject arbitrary web script or HTML via multiple vectors in (1) login/profile.php, (2) login/userinfo.php, (3) admin/admin.php, (4) imcenter.php, ... Read more
Affected Products : phpkit- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3550
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the id_user parameter.... Read more
Affected Products : toendacms- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-3543
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter.... Read more
Affected Products : phorum- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3546
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege.... Read more
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3551
toendaCMS before 0.6.2 stores user account and session data in the web root directory, which allows remote attackers to obtain sensitive information via a direct request to the appropriate XML file.... Read more
Affected Products : toendacms- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3544
Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.... Read more
Affected Products : xmb- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3558
PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1) page and (2) site parameters.... Read more
Affected Products : oste- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3578
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.... Read more
Affected Products : walla_telesite- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3557
Directory traversal vulnerability in admin/defaults.php in PHPlist 2.10.1 and earlier allows remote attackers to access arbitrary files via a .. (dot dot) in the selected%5B%5D parameter in an HTTP POST request.... Read more
Affected Products : phplist- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3581
GDAL before 1.3.0-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.... Read more
Affected Products : gdal- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3572
SQL injection vulnerability in index.php in Peel 2.6 through 2.7 allows remote attackers to execute arbitrary SQL commands via the rubid parameter.... Read more
Affected Products : peel- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-3589
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal crash) via a long USER ftp command.... Read more
Affected Products : filezilla_server_terminal- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3564
envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.... Read more
Affected Products : hp-ux- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025