Latest CVE Feed
-
4.6
MEDIUMCVE-2005-2071
traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).... Read more
Affected Products : solaris- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2070
The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.... Read more
Affected Products : sendmail- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2058
Multiple SQL injection vulnerabilities in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to execute arbitrary SQL commands via the Number parameter to (1) download.php, (2) modifypost.php, (3) mailthread.php, or (4) notifymod.php, (5) month ... Read more
Affected Products : ubb.threads- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2066
SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.... Read more
Affected Products : asp-nuke- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2065
HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode parameter.... Read more
Affected Products : asp-nuke- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2076
HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.... Read more
Affected Products : version_control_repository_manager- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2073
Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.... Read more
Affected Products : db2- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2077
Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.... Read more
Affected Products : hosting_controller- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2060
Multiple HTTP Response Splitting vulnerabilities in (1) toggleshow.php, (2) togglecats.php, and (3) showprofile.php in Infopop UBB.Threads before 6.5.2 Beta allow remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in... Read more
Affected Products : ubb.threads- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2062
Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands via the catid parameter to (1) default.asp or (2) buyersend.asp, (3) Administrator ID field in admin.asp, E-mail field in (4) advertise... Read more
Affected Products : activebuyandsell- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2075
PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administrat... Read more
Affected Products : php_fusion- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2055
RealPlayer 8, 10, 10.5 (6.0.12.1040-1069), and Enterprise and RealOne Player v1 and v2 allows remote malicious web server to create an arbitrary HTML file that executes an RM file via "default settings of earlier Internet Explorer browsers".... Read more
- Published: Jun. 29, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1766
Heap-based buffer overflow in rtffplin.cpp in RealPlayer 10.5 6.0.12.1056 on Windows, and 10, 10.0.1.436, and other versions before 10.0.5 on Linux, allows remote attackers to execute arbitrary code via a RealMedia file with a long RealText string, such a... Read more
Affected Products : realplayer- Published: Jun. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0772
VERITAS Backup Exec 9.0 through 10.0 for Windows Servers, and 9.0.4019 through 9.1.307 for Netware, allows remote attackers to cause a denial of service (Remote Agent crash) via (1) a crafted packet in NDMLSRVR.DLL or (2) a request packet with an invalid ... Read more
Affected Products : backup_exec- Published: Jun. 28, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-2052
Heap-based buffer overflow in vidplin.dll in RealPlayer 10 and 10.5 (6.0.12.1040 through 1069), RealOne Player v1 and v2, RealPlayer 8 and RealPlayer Enterprise allows remote attackers to execute arbitrary code via an .avi file with a modified strf struct... Read more
- Published: Jun. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2051
Buffer overflow in the VERITAS Backup Exec Web Administration Console (BEWAC) 9.0 4367 through 10.0 rev. 5484 allows remote attackers to execute arbitrary code.... Read more
Affected Products : backup_exec- Published: Jun. 28, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2050
Unknown vulnerability in Tor before 0.1.0.10 allows remote attackers to read arbitrary memory and possibly key information from the exit server's process space.... Read more
Affected Products : tor- Published: Jun. 28, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2053
Just another flat file (JAF) CMS before 3.0 Final allows remote attackers to obtain sensitive information via (1) an * (asterisk) in the id parameter, (2) a blank id parameter, or (3) an * (asterisk) in the disp parameter to index.php, which reveals the p... Read more
Affected Products : jaf_cms- Published: Jun. 28, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1759
Race condition in shtool 2.0.1 and earlier allows local users to modify or create arbitrary files via a symlink attack on temporary files after they have been created, a different vulnerability than CVE-2005-1751.... Read more
Affected Products : shtool- Published: Jun. 28, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0771
VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calling methods to the RPC interface on TCP port 6106.... Read more
- Published: Jun. 23, 2005
- Modified: Apr. 03, 2025