Latest CVE Feed
-
4.3
MEDIUMCVE-2005-1587
Cross-site scripting (XSS) vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to inject arbitrary web script or HTML via the sWord parameter.... Read more
Affected Products : quick.cart- EPSS Score: %0.53
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1583
1Two News 1.0 allows remote attackers to (1) delete images for new stories via a direct request to admin/delete.php or (2) upload arbitrary images via a direct request to admin/upload.php.... Read more
Affected Products : 1two_news- EPSS Score: %0.40
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1545
Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow.... Read more
Affected Products : ht_editor- EPSS Score: %2.91
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1552
GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, which may allow remote attackers to gain sensitive information via a direct re... Read more
Affected Products : digital_surveillance_system- EPSS Score: %5.02
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1554
SQL injection vulnerability in view_user.php in WowBB 1.6, 1.61, and 1.62 allows remote attackers to execute arbitrary SQL commands via the sort_by parameter.... Read more
Affected Products : wowbb_web_forum- EPSS Score: %0.74
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1577
APG Technology ClassMaster does not properly restrict access to sensitive folders, which allows remote attackers to access folders via a network share.... Read more
Affected Products : classmaster- EPSS Score: %0.66
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1550
easymsgb.pl in Easy Message Board allows remote attackers to execute arbitrary commands via shell metacharacters in the print parameter.... Read more
Affected Products : easy_message_board- EPSS Score: %6.58
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1570
forum.asp in bttlxeForum 2.0 allows remote attackers to obtain full path information via a certain hex-encoded argument to the page parameter, possibly due to a SQL injection vulnerability.... Read more
Affected Products : bttlxeforum- EPSS Score: %0.34
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1546
Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.... Read more
Affected Products : ht_editor- EPSS Score: %2.91
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1544
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.... Read more
Affected Products : libtiff- EPSS Score: %15.65
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1563
Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.... Read more
Affected Products : bugzilla- EPSS Score: %0.81
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1548
SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.... Read more
Affected Products : advanced_guestbook- EPSS Score: %0.29
- Published: May. 14, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1578
EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide information without detection.... Read more
Affected Products : encase- EPSS Score: %0.07
- Published: May. 13, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0758
zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.... Read more
- EPSS Score: %0.15
- Published: May. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1531
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a ... Read more
- EPSS Score: %2.20
- Published: May. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1567
SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.... Read more
Affected Products : directtopics- EPSS Score: %0.43
- Published: May. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1565
Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.... Read more
Affected Products : bugzilla- EPSS Score: %0.80
- Published: May. 12, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0971
Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.... Read more
Affected Products : mac_os_x- EPSS Score: %0.08
- Published: May. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0974
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.... Read more
Affected Products : mac_os_x- EPSS Score: %0.06
- Published: May. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0972
Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.... Read more
- EPSS Score: %0.31
- Published: May. 12, 2005
- Modified: Apr. 03, 2025