Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2333
Cross-site scripting (XSS) vulnerability in smilies_popup.php in SEO-Board 1.0 allows remote attackers to inject arbitrary web script or HTML via the doc parameter.... Read more
Affected Products : seo-board- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2328
PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.... Read more
Affected Products : laffer- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2331
PHP remote file inclusion vulnerability in display.php in MooseGallery allows remote attackers to execute arbitrary PHP code via the type parameter.... Read more
Affected Products : moosegallery- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2332
Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a allows remote attackers to inject arbitrary web script or HTML via the username parameter to (1) admin.php or (2) login.php.... Read more
Affected Products : phppageprotect- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2330
Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.... Read more
Affected Products : oscommerce- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2329
MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to access the consoles of other users.... Read more
- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2327
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web script or HTML via nested [url] BBCode tags.... Read more
Affected Products : e107- Published: Jul. 20, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2300
Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file.... Read more
Affected Products : skype- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2321
PHP remote file inclusion vulnerability in CaLogic 1.2.2 allows remote attackers to execute arbitrary code via the CLPATH parameter to (1) cl_minical.php, (2) clmcpreload.php, (3) mcconfig.php, or (4) mcpi-demo.php.... Read more
Affected Products : calogic- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2005-2306
Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated users to gain privileges as other users.... Read more
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2308
The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as demonstrated using (1) mov_fencepost.jpg, (2) cmp_fence... Read more
Affected Products : ie- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2005-2310
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.... Read more
Affected Products : winamp- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2307
netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."... Read more
- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2298
BitDefender Engine 1.6.1 and earlier does not properly scan all attachments, which allows remote attackers to bypass virus scanning via begin and end commands in the body of the e-mail, which BitDefender treats as a uuencoded attachment and stops scanning... Read more
Affected Products : bitdefender_engine- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2318
Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : dvbbs- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2325
Clever Copy 2.0 and 2.0a allows remote attackers to obtain the full path of the web root via a direct request to (1) ticker.php, (2) menu.php, (3) banned.php, (4) endlayout.php, (5) randomhlinesblock.php, (6) showlast.php, (7) showlast5class1.php, (8) sho... Read more
Affected Products : clever_copy- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2305
DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via a long message to TCP port 1071 or 1073, possibly due to a buffer overflow.... Read more
Affected Products : remote_control_server- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2317
Shorewall 2.4.x before 2.4.1, 2.2.x before 2.2.5, and 2.0.x before 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with an accepted MAC address to bypass other firewall rules or policies.... Read more
Affected Products : shorewall- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2313
Check Point SecuRemote NG with Application Intelligence R54 allows attackers to obtain credentials and gain privileges via unknown attack vectors.... Read more
Affected Products : secureclient_ng- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2314
inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator's username and password by setting the do_login parameter and performing an edit action using user.php, which causes the login check to be bypassed and leaks the... Read more
Affected Products : phpsftpd- Published: Jul. 19, 2005
- Modified: Apr. 03, 2025