Latest CVE Feed
-
6.8
MEDIUMCVE-2005-1436
Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php, (4)... Read more
Affected Products : osticket- EPSS Score: %2.08
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1415
Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.... Read more
Affected Products : secure_ftp_server- EPSS Score: %70.62
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0106
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.... Read more
Affected Products : ubuntu_linux- EPSS Score: %0.06
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1376
Multiple directory traversal vulnerabilities in (1) document.php or (2) insertMyDoc.php in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote project administrators to upload arbitrary files.... Read more
Affected Products : claroline- EPSS Score: %0.93
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1383
The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.... Read more
Affected Products : application_server- EPSS Score: %60.99
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1410
The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a de... Read more
- EPSS Score: %0.10
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1440
Multiple cross-site scripting (XSS) vulnerabilities in ViArt Shop Enterprise 2.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) various parameters to basket.php, (2) the nickname, email, topic, and message fields in forum.php, as ... Read more
Affected Products : viart_shop_enterprise- EPSS Score: %3.05
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1427
Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.... Read more
Affected Products : uphotogallery- EPSS Score: %1.02
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1451
The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.... Read more
Affected Products : serendipity- EPSS Score: %0.72
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1393
Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.... Read more
Affected Products : arcinfo_workstation- EPSS Score: %0.09
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1402
Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in ... Read more
Affected Products : mtp-target- EPSS Score: %5.90
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1404
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.... Read more
Affected Products : myphp_forum- EPSS Score: %0.98
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1414
ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.... Read more
Affected Products : filepocket- EPSS Score: %0.15
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1421
Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via ".." (dot dot) sequences in an HTTP request.... Read more
Affected Products : video_cam_server- EPSS Score: %0.25
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1424
StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.... Read more
Affected Products : gotext- EPSS Score: %0.17
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1429
SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : wwwguestbook- EPSS Score: %0.49
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1401
Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.... Read more
Affected Products : mtp-target- EPSS Score: %12.89
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-1423
Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.... Read more
Affected Products : 602lan_suite- EPSS Score: %3.39
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0601
Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain access.... Read more
Affected Products : application_and_content_networking_software- EPSS Score: %0.74
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1358
text.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.... Read more
Affected Products : text.cgi- EPSS Score: %0.90
- Published: May. 02, 2005
- Modified: Apr. 03, 2025