Latest CVE Feed
-
2.1
LOWCVE-2005-2451
Cisco IOS 12.0 through 12.4 and IOS XR before 3.2, with IPv6 enabled, allows remote attackers on a local network segment to cause a denial of service (device reload) and possibly execute arbitrary code via a crafted IPv6 packet.... Read more
- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2450
Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message.... Read more
Affected Products : clamav- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1853
gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.... Read more
Affected Products : gopher- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2438
Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value.... Read more
Affected Products : usebb- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2413
PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.... Read more
Affected Products : atomic_photo_album- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2437
Website Baker Project does not properly verify the file extensions of uploaded files, which allows remote attackers to upload and execute arbitrary PHP code.... Read more
Affected Products : website_baker- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2421
Multiple SQL injection vulnerabilities in index.php and other pages in Beehive Forum allow remote attackers to execute arbitrary SQL commands via the webtag parameter.... Read more
Affected Products : beehive_forum- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2430
Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to det... Read more
Affected Products : gforge- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2346
Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section.... Read more
Affected Products : groupwise- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2423
Beehive Forum allows remote attackers to obtain sensitive information via (1) an invalid final_uri or sort_by parameter to index.php or a direct request to (2) admin.php, (3) attachments.inc.php, (4) banned.inc.php, (5) beehive.inc.php, (6) constants.inc.... Read more
Affected Products : beehive_forum- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2412
PHP remote file inclusion vulnerability in block.php in PHP FirstPost allows remote attackers to execute arbitrary PHP code via the Include parameter.... Read more
Affected Products : php_firstpost- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2439
SQL injection vulnerability in UseBB 0.5.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search function.... Read more
Affected Products : usebb- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2417
Contrexx before 1.0.5 allows remote attackers to obtain sensitive information via a direct request to /config/version.xml.... Read more
Affected Products : contrexx- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2442
Cross-Application Scripting (XAS) vulnerability in SPI Dynamics WebInspect 5.0.196 allows remote attackers to inject Javascript from one application into another.... Read more
Affected Products : webinspect- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2443
Kshout 2.x and 3.x stores settings.dat under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.... Read more
Affected Products : kshout- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2448
Multiple "endianness errors" in libgadu in ekg before 1.6rc2 allow remote attackers to cause a denial of service (invalid behavior in applications) on big-endian systems.... Read more
Affected Products : ekg- Published: Aug. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1762
The ptrace call in the Linux kernel 2.6.8.1 and 2.6.10 for the AMD64 platform allows local users to cause a denial of service (kernel crash) via a "non-canonical" address.... Read more
Affected Products : linux_kernel- Published: Aug. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2079
Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code.... Read more
- Published: Aug. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2409
Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.... Read more
Affected Products : nbsmtp- Published: Aug. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2405
Opera 8.01, when the "Arial Unicode MS" font (ARIALUNI.TTF) is installed, does not properly handle extended ASCII characters in the file download dialog box, which allows remote attackers to spoof file extensions and possibly trick users into executing ar... Read more
Affected Products : opera_browser- Published: Aug. 01, 2005
- Modified: Apr. 03, 2025