Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2650
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.... Read more
Affected Products : emefa_guestbook- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2665
Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote attackers to execute arbitrary code via an e-mail message with a long Expires header.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2637
Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php.... Read more
Affected Products : phpfreenews- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2652
Zorum 3.5 allows remote attackers to obtain the full installation path via direct requests to (1) gorum/notification.php, (2) user.php, (3) attach.php, (4) blacklist.php, (5) zorum/forum.php, (6) globalstat.php, (7) gorum/trace.php, (8) gorum/badwords.php... Read more
Affected Products : zorum- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2632
SQL injection vulnerability in login_admin_mediabox404.php in mediabox404 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the User field.... Read more
Affected Products : mediabox404- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2633
Multiple PHP file inclusion vulnerabilities in (1) admin_o.php, (2) board_o.php, (3) dev_o.php, (4) file_o.php or (5) tech_o.php in PHPTB Topic Board 2.0 and earlier allow remote attackers to execute arbitrary PHP code via the absolutepath parameter.... Read more
Affected Products : topic_boards- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2644
Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Jtext field.... Read more
Affected Products : jaguarcontrol- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2499
slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.... Read more
Affected Products : slocate- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2670
Directory traversal vulnerability in HAURI Anti-Virus products including ViRobot Expert 4.0, Advanced Server, Linux Server 2.0, and LiveCall allows remote attackers to overwrite arbitrary files via ".." sequences in filenames contained in (1) ACE, (2) ARJ... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2677
ACNews stores the database in a file under the web document root with a db.inc extension and insufficient access control, which allows remote attackers to obtain sensitive information such as the full pathname of the server.... Read more
Affected Products : acnews- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2641
Unknown vulnerability in pam_ldap before 180 does not properly handle a new password policy control, which could allow attackers to gain privileges. NOTE: CVE-2005-2497 had also been assigned to this issue, but CVE-2005-2641 is the correct candidate.... Read more
Affected Products : pam_ldap- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2622
Cross-site scripting (XSS) vulnerability in index.php in ECW-Shop 6.0.2 allows remote attackers to inject arbitrary web script or HTML via the (1) max or (2) ctg parameter.... Read more
Affected Products : ecw-shop- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2508
dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.... Read more
- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2627
Multiple integer underflows in Kismet before 2005-08-R1 allow remote attackers to execute arbitrary code via (1) kernel headers in a pcap file or (2) data frame dissection, which leads to heap-based buffer overflows.... Read more
Affected Products : kismet- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2623
ECW-Shop 6.0.2 allows remote attackers to reduce the total cost of their shopping cart by specifying a negative quantity for an item, which causes the price of the item to be subtracted from the total cost.... Read more
Affected Products : ecw-shop- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2510
The Server Admin tool in servermgr_ipfilter for Mac OS X 10.4 to 10.4.2, when using multiple subnets and Address Groups, does not always properly write firewall rules to the Active Rules when certain conditions occur, which could result in firewall polici... Read more
Affected Products : mac_os_x_server- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2625
Incomplete blacklist vulnerability in the checkBlacklist function in CPAINT allows remote attackers to execute arbitrary commands via the (1) ExecuteGlobal function or (2) GetRef statement, which is not included in the blacklist.... Read more
Affected Products : cpaint- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2624
Eval injection vulnerability in CPAINT 1.3-SP allows remote attackers to execute arbitrary ASP code via the cpaint_argument[] parameter to (1) calculator.asp or (2) cpaintfile.asp, which is directly fed into an eval statement.... Read more
Affected Products : cpaint- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-2502
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execute arbitrary code via a crafted Microsoft Word file.... Read more
- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2504
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid.... Read more
- Published: Aug. 19, 2005
- Modified: Apr. 03, 2025