Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2563
Multiple cross-site scripting (XSS) vulnerabilities in Gravity Board X (GBX) 1.1 allow remote attackers to inject arbitrary web script or HTML via (1) the board_id parameter to deletethread.php or (2) the template.... Read more
Affected Products : gravity_board_x- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2498
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nes... Read more
- Published: Aug. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1527
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call... Read more
- Published: Aug. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2549
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list da... Read more
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2553
The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program... Read more
Affected Products : linux_kernel- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2550
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects... Read more
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2551
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.... Read more
Affected Products : edirectory- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2552
Unknown vulnerability in HP ProLiant DL585 servers running Integrated Lights Out (ILO) firmware before 1.81 allows attackers to access server controls when the server is "powered down."... Read more
Affected Products : proliant_dl585- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2554
The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.... Read more
Affected Products : epolicy_orchestrator_agent- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2548
vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snm... Read more
Affected Products : linux_kernel- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2547
security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.... Read more
Affected Products : bluez- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2535
Buffer overflow in the Discovery Service in BrightStor ARCserve Backup 9.0 through 11.1 allows remote attackers to execute arbitrary commands via a large packet to TCP port 41523, a different vulnerability than CVE-2005-0260.... Read more
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2546
Arab Portal 2.0 allows remote attackers to obtain sensitive information via a long (1) username or (2) password, which reveals the path in an error message when the undefined "errmsg" function is called.... Read more
Affected Products : arab_portal- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2538
FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via (1) a null byte or (2) an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1 in the mod parameter.... Read more
Affected Products : flatnuke- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2361
Unknown vulnerability in the (1) AgentX dissector, (2) PER dissector, (3) DOCSIS dissector, (4) SCTP graphs, (5) HTTP dissector, (6) DCERPC, (7) DHCP, (8) RADIUS dissector, (9) Telnet dissector, (10) IS-IS LSP dissector, or (11) NCP dissector in Ethereal ... Read more
Affected Products : ethereal- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1218
The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.... Read more
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2365
Unknown vulnerability in the SMB dissector in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a buffer overflow or a denial of service (memory consumption) via unknown attack vectors.... Read more
Affected Products : ethereal- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1981
Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.... Read more
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2540
CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the signature field, which is injected into a PHP script without a preceding c... Read more
Affected Products : flatnuke- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-1982
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller w... Read more
- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025