Latest CVE Feed
-
7.5
HIGHCVE-2005-2819
DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php.... Read more
Affected Products : downfile- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2816
Cross-site scripting (XSS) vulnerability in Greymatter allows remote attackers to inject arbitrary web script or HTML via a post comment, which is recorded in a log file but not properly handled when the administrator uses "View Control Panel Log" to read... Read more
Affected Products : greymatter_forum- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2811
Untrusted search path vulnerability in Net-SNMP 5.2.1.2 and earlier, on Gentoo Linux, installs certain Perl modules with an insecure DT_RPATH, which could allow local users to gain privileges.... Read more
Affected Products : net-snmp- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2794
store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.... Read more
Affected Products : squid- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2796
The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.... Read more
Affected Products : squid- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2808
frox 0.7.16 and 0.7.17 does not properly parse certain Deny ACLs, which might allow attackers to bypass intended restrictions and access blocked hosts.... Read more
Affected Products : frox- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2812
man2web allows remote attackers to execute arbitrary commands via -P arguments.... Read more
Affected Products : man2web- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2809
silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file.... Read more
Affected Products : secure_internet_live_conferencing- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2814
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.... Read more
Affected Products : flatnuke- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2810
Multiple stack-based buffer overflows in urban before 1.5.3 allow local users to gain privileges via a long HOME environment variable to (1) config.cc, (2) game.cc, (3) highscor.cc, or (4) meny.cc.... Read more
Affected Products : urban- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2815
print.php in FlatNuke 2.5.6 allows remote attackers to obtain sensitive information (path disclosure on error) or cause a denial of service (resource consumption) via an MS-DOS device name in the news parameter to print.php, such as (1) AUX, (2) CON, (3) ... Read more
Affected Products : flatnuke- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2807
frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows local users to read portions of arbitrary files via the -f command line option.... Read more
Affected Products : frox- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2813
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) characters in the id parameter to the read mod in index.php.... Read more
Affected Products : flatnuke- Published: Sep. 07, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2494
kcheckpass in KDE 3.2.0 up to 3.4.2 allows local users to gain root access via a symlink attack on lock files.... Read more
- Published: Sep. 06, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2656
Polygen before 1.0.6 generates precompiled grammar objects with world-writable permissions, which allows local users to cause a denial of service (disk consumption) and possibly perform other unauthorized activities.... Read more
Affected Products : polygen- Published: Sep. 06, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2700
ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended a... Read more
- Published: Sep. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2763
Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.... Read more
Affected Products : openttd- Published: Sep. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2806
client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field na... Read more
Affected Products : bnbt- Published: Sep. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2805
forum_post.php in e107 0.6 allows remote attackers to post to non-existent forums by modifying the forum number.... Read more
Affected Products : e107- Published: Sep. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2803
Cross-site scripting (XSS) vulnerability in Hiki 0.8.1 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via a page name in a Login link, a different vulnerability than CVE-2005-2336.... Read more
Affected Products : hiki- Published: Sep. 06, 2005
- Modified: Apr. 03, 2025