Latest CVE Feed
-
4.3
MEDIUMCVE-2005-4295
Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from thi... Read more
Affected Products : absolute_image_gallery_xe- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4293
Cross-site scripting (XSS) vulnerability in cp-app.cgi in ClickCartPro (CCP) 5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the affl parameter.... Read more
Affected Products : clickcartpro- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3253
Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and AP-2000 before 2.5.5, and Proxim AP-700 and AP-4000 after 2.4.11 and before 3.1, use a static WEP key of "... Read more
Affected Products : wireless_ap-3 wireless_ap-4 wireless_ap-5 wireless_ap-6 wireless_ap-7 wireless_ap-8 ap-2000 ap-4000 ap-600 ap-700- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4287
PHP remote file include vulnerability in MarmaraWeb E-commerce allows remote attackers to execute arbitrary code via the page parameter to index.php.... Read more
Affected Products : marmaraweb_e-commerce- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4281
Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to zaygo.cgi.... Read more
Affected Products : hostingcart- Published: Dec. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-4271
Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.... Read more
Affected Products : aix- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-4272
Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.... Read more
Affected Products : aix- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-4273
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.... Read more
Affected Products : aix- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-4274
Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related to "authentication mechanisms" and "form input."... Read more
Affected Products : webintelligence- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4269
mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in ... Read more
- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4270
Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.... Read more
Affected Products : appscan_qa- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
3.7
LOWCVE-2005-4268
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.... Read more
Affected Products : cpio- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4262
Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid parameter. NOTE: this issue might be resultant from the SQL injection problem (CVE... Read more
Affected Products : envolution- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4248
Multiple cross-site scripting (XSS) vulnerabilities in QuickPayPro 3.1 allow remote attackers to inject arbitrary web script or HTML via various fields, such as those in (1) communication/subscribers.tracking.add.php, (2) support/tickets.add.php, and (3) ... Read more
Affected Products : quickpaypro- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4263
SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter.... Read more
Affected Products : envolution- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4243
Multiple SQL injection vulnerabilities in QuickPayPro 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) popupid parameter in popups.edit.php; (2) so, (3) sb, and (4) nr parameters in customer.tickets.view.php; (5) subrackingid param... Read more
Affected Products : quickpaypro- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4259
Multiple SQL injection vulnerabilities in ASPBB 0.4 allow remote attackers to execute arbitrary SQL commands via the (1) TID parameter in topic.asp, (2) FORUM_ID parameter in forum.asp, and (3) PROFILE_ID parameter in profile.asp. NOTE: the provenance of... Read more
Affected Products : aspbb- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-4261
Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectors, related to "a possible security flaw caused by a bug in Perl." NOTE: unless CP+ includes its own copy of Perl ... Read more
Affected Products : cp\+- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-4255
Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter.... Read more
Affected Products : wikkawiki- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-4254
SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : dream_poll- Published: Dec. 15, 2005
- Modified: Apr. 03, 2025