Latest CVE Feed
-
5.0
MEDIUMCVE-2005-1420
Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to determine the full pathname of the server via a request for an invalid page, as demonstrated using "%20" (hex-encoded space).... Read more
Affected Products : video_cam_server- EPSS Score: %0.41
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1428
edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.... Read more
Affected Products : uphotogallery- EPSS Score: %0.76
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1442
Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.... Read more
Affected Products : lotus_notes- EPSS Score: %0.09
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1378
SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.... Read more
Affected Products : phpbb_personal_notes_module- EPSS Score: %0.88
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1393
Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.... Read more
Affected Products : arcinfo_workstation- EPSS Score: %0.09
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1421
Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via ".." (dot dot) sequences in an HTTP request.... Read more
Affected Products : video_cam_server- EPSS Score: %0.25
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1404
MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.... Read more
Affected Products : myphp_forum- EPSS Score: %0.98
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1414
ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.... Read more
Affected Products : filepocket- EPSS Score: %0.15
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1402
Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in ... Read more
Affected Products : mtp-target- EPSS Score: %5.90
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1401
Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.... Read more
Affected Products : mtp-target- EPSS Score: %12.89
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1429
SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : wwwguestbook- EPSS Score: %0.49
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1424
StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.... Read more
Affected Products : gotext- EPSS Score: %0.17
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1395
Buffer overflow in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier may allow local users to gain privileges via a long (1) XAPPLRESLANGPATH or (2) XAPPLRESDIR environment variable, or (3) command line argument.... Read more
Affected Products : ce_ceterm- EPSS Score: %0.05
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1426
Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).... Read more
Affected Products : ublog- EPSS Score: %0.43
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1396
Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.... Read more
Affected Products : ce_ceterm- EPSS Score: %0.17
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1450
Unknown vulnerability in "the function used to validate path-names for uploading media" in Serendipity before 0.8 has unknown impact.... Read more
Affected Products : serendipity- EPSS Score: %0.53
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1413
Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username or (2) password parameters to admin_login.asp, or the (3) searchstring and possibly (4) ID parameters to... Read more
Affected Products : envivo_cms- EPSS Score: %2.22
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1403
Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters t... Read more
Affected Products : amazon_webstore- EPSS Score: %1.92
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1447
PHP remote file inclusion vulnerability in main.php in SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to execute arbitrary PHP code via the p parameter.... Read more
Affected Products : sitepanel- EPSS Score: %0.89
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1431
The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.... Read more
- EPSS Score: %1.37
- Published: May. 03, 2005
- Modified: Apr. 03, 2025