Latest CVE Feed
-
9.3
HIGHCVE-2005-4867
Stack-based buffer overflow in the SATENCRYPT function in IBM DB2 8.1, when Satellite Administration (SATADMIN) is enabled, allows remote attackers to execute arbitrary code via a long parameter.... Read more
Affected Products : db2_universal_database- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-2714
passwd in Directory Services in Mac OS X 10.3.x before 10.3.9 and 10.4.x before 10.4.5 allows local users to overwrite arbitrary files via a symlink attack on the .pwtmp.[PID] temporary file.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3713
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a GIF image file with a crafted Netscape Navigator Application Extension Block that modifies the heap in the Picture Modifier block.... Read more
Affected Products : quicktime- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4664
SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the logon page, a different vulnerability than CVE-2005-4662.... Read more
Affected Products : ocomon- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4613
Cross-site scripting (XSS) vulnerability in VUBB alpha rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified fields in the user edit profile.... Read more
Affected Products : vubb- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4649
Multiple cross-site scripting (XSS) vulnerabilities in Advanced Guestbook 2.2 and 2.3.1 allow remote attackers to inject arbitrary web script or HTML via (1) the entry parameter in index.php and (2) the gb_id parameter in comment.php. NOTE: The index.php... Read more
Affected Products : advanced_guestbook- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4755
BEA WebLogic Server and WebLogic Express 8.1 SP3 and earlier (1) stores the private key passphrase (CustomTrustKeyStorePassPhrase) in cleartext in nodemanager.config; or, during domain creation with the Configuration Wizard, renders an SSL private key pas... Read more
Affected Products : weblogic_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4723
D-Link DI-524 Wireless Router, DI-624 Wireless Router, and DI-784 allow remote attackers to cause a denial of service (device reboot) via a series of crafted fragmented UDP packets, possibly involving a missing fragment.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4656
SQL injection vulnerability in index.php in TClanPortal 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands, and retrieve all usernames and passwords, via the id parameter.... Read more
Affected Products : tclanportal- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4815
SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers ... Read more
Affected Products : sap_r_3- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3659
nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denia... Read more
Affected Products : legato_networker- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4813
Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal Reports Server XI, and BusinessObjects Enterprise XI, allows remote attackers to cause a denial of service ... Read more
Affected Products : crystal_enterprise_xi crystal_reports_server_xi crystal_reports_xi report_application_server- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-4736
IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows remote authenticated users to cause a denial of service (disk consumption) via a hash join (hsjn) that triggers an infinite loop in sqlri_hsjnFlushBlocks.... Read more
Affected Products : db2_universal_database- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3628
Buffer overflow in the JBIG2Bitmap::JBIG2Bitmap function in JBIG2Stream.cc in Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to modify memory and possibly execute arbitrary code vi... Read more
Affected Products : xpdf- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2340
Heap-based buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a crafted (1) QuickTime Image File (QTIF), (2) PICT, or (3) JPEG format image with a long data field.... Read more
Affected Products : quicktime- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3625
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) D... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_desktop poppler xpdf suse_linux linux xpdf kdegraphics kpdf +26 more products- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4619
SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.... Read more
Affected Products : zorum- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4831
viewcvs in ViewCVS 0.9.2 allows remote attackers to set the Content-Type header to arbitrary values via the content-type parameter, which can be leveraged for cross-site scripting (XSS) and other attacks, as demonstrated using (1) "text/html", or (2) "ima... Read more
Affected Products : viewcvs- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4871
Certain XML functions in IBM DB2 8.1 run with the privileges of DB2 instead of the logged-in user, which allows remote attackers to create or overwrite files via (1) XMLFileFromVarchar or (2) XMLFileFromClob, or read files via (3) XMLVarcharFromFile or (4... Read more
Affected Products : db2- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-3706
Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent attackers to execute arbitrary code by causing an application that uses LibSystem to request a large amount of memory.... Read more
- Published: Dec. 31, 2005
- Modified: Apr. 03, 2025