Latest CVE Feed
-
7.5
HIGHCVE-2005-1383
The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.... Read more
Affected Products : application_server- EPSS Score: %60.99
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1414
ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.... Read more
Affected Products : filepocket- EPSS Score: %0.15
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1401
Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.... Read more
Affected Products : mtp-target- EPSS Score: %12.89
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1402
Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in ... Read more
Affected Products : mtp-target- EPSS Score: %5.90
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1404
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.... Read more
Affected Products : myphp_forum- EPSS Score: %0.98
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1424
StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.... Read more
Affected Products : gotext- EPSS Score: %0.17
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1393
Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.... Read more
Affected Products : arcinfo_workstation- EPSS Score: %0.09
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1421
Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via ".." (dot dot) sequences in an HTTP request.... Read more
Affected Products : video_cam_server- EPSS Score: %0.25
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1429
SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : wwwguestbook- EPSS Score: %0.49
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1441
Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).... Read more
Affected Products : lotus_domino- EPSS Score: %1.43
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1825
Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameter... Read more
Affected Products : radia_client- EPSS Score: %21.09
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1416
Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.... Read more
Affected Products : 04webserver- EPSS Score: %0.25
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1452
Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."... Read more
Affected Products : serendipity- EPSS Score: %0.38
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1411
Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain privileges.... Read more
Affected Products : icuii- EPSS Score: %0.22
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1407
Skype for Windows 1.2.0.0 to 1.2.0.46 allows local users to bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.... Read more
Affected Products : skype- EPSS Score: %0.06
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1387
Cocktail 3.5.4 and possibly earlier in Mac OS X passes the administrative password on the command line to sudo in cleartext, which allows local users to gain sensitive information by running listing processes.... Read more
Affected Products : cocktail- EPSS Score: %0.05
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1422
Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to conduct administrator operations and cause a denial of service (server or camera shutdown) via a direct request to admin.html.... Read more
Affected Products : video_cam_server- EPSS Score: %0.76
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1433
Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.... Read more
Affected Products : openview_event_correlation_services- EPSS Score: %0.11
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1374
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php... Read more
Affected Products : claroline- EPSS Score: %2.57
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1448
Cross-site scripting (XSS) vulnerability in the BBCode plugin for Serendipity before 0.8 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : serendipity- EPSS Score: %1.01
- Published: May. 03, 2005
- Modified: Apr. 03, 2025