Latest CVE Feed
-
7.5
HIGHCVE-2005-4569
Stack-based buffer overflow in index.fts in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (aka Build 4.4.000 Oct 26 2005) allows remote attackers to execute arbitrary code via a long tzoffset value.... Read more
Affected Products : ftgate- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4577
Multiple cross-site scripting (XSS) vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to inject arbitrary web script or HTML via unkno... Read more
Affected Products : business_logic- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4570
The Internet Key Exchange version 1 (IKEv1) implementations in Fortinet FortiOS 2.50, 2.80 and 3.0, FortiClient 2.0,; and FortiManager 2.80 and 3.0 allow remote attackers to cause a denial of service (termination of a process that is automatically restart... Read more
- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4576
Multiple cross-site scripting (XSS) vulnerabilities in the UpdateEngine program in Fatwire UpdateEngine 6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) COUNTRYNAME, (2) EMAIL, and (3) FUELAP_TEMPLATENAME parameter... Read more
Affected Products : updateengine- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4565
Format string vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via format string specifiers in crafted IKE packets, as demonstrated by t... Read more
Affected Products : netvanta- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4572
Multiple SQL injection vulnerabilities in myEZshop Shopping Cart allow remote attackers to execute arbitrary SQL commands via the (1) GroupsId and (2) ItemsId parameters in admin.php. NOTE: the provenance of this information is unknown; the details are o... Read more
Affected Products : myezshop_shopping_cart- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4580
Cross-site scripting (XSS) vulnerability in Day Communique 4 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search.... Read more
Affected Products : communique- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-4581
Buffer overflow in Electric Sheep 2.6.3 client allows local users to execute arbitrary code via a long window-id parameter. NOTE: because the program is not setuid and not normally called from remote programs, there may not be a typical attack vector for ... Read more
Affected Products : electric_sheep- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4574
Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.... Read more
Affected Products : commonspot_content_server- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4579
Multiple HTTP response splitting vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to inject arbitrary HTTP headers via unknown attack... Read more
Affected Products : business_logic- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4566
Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.... Read more
Affected Products : netvanta- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4563
SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875.... Read more
Affected Products : enterprise_connector- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4578
Multiple SQL injection vulnerabilities in Hitachi Business Logic - Container (BLC) P-2443-9114 01-00 through 02-06 on Windows, and P-1M43-9111 01-01 through 02-00 on AIX, allow remote attackers to execute arbitrary SQL commands via unknown attack vectors ... Read more
Affected Products : business_logic- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2005-4567
Multiple cross-site scripting (XSS) vulnerabilities in FTGate Technology (formerly known as Floosietek) FTGate 4.4 (Build 4.4.000 Oct 26 2005) allow remote attackers to inject arbitrary web script or HTML by sending (1) the href parameter to index.fts, or... Read more
Affected Products : ftgate- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4585
Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.... Read more
Affected Products : ethereal- Published: Dec. 29, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3345
rssh 2.0.0 through 2.2.3 allows local users to bypass access restrictions and gain root privileges by using the rssh_chroot_helper command to chroot to an external directory.... Read more
Affected Products : rssh- Published: Dec. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4560
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Pictur... Read more
- Published: Dec. 28, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4550
The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).... Read more
Affected Products : application_server_discussion_forum_portlet- Published: Dec. 28, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4557
dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directo... Read more
- Published: Dec. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4553
Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long APPE command. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.... Read more
Affected Products : golden_ftp_server- Published: Dec. 28, 2005
- Modified: Apr. 03, 2025