Latest CVE Feed
-
7.2
HIGHCVE-2005-2227
Softiacom wMailserver 1.0 stores passwords in plaintext in the Darsite\MAILSRV\Admin key, which allows local users to gain administrator privileges.... Read more
Affected Products : wmailserver- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2229
Blog Torrent 0.92 and earlier stores sensitive files under the web document root in the (1) data or (2) torrents directories with insufficient access control, which allows remote attackers to obtain sensitive information such as account names and password... Read more
Affected Products : blog_torrent- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2228
Web Wiz Forums 7.9 and 8.0 allows remote attackers to view message titles of a hidden forum.... Read more
Affected Products : web_wiz_forums- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2236
Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.... Read more
Affected Products : aix- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2226
Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.... Read more
Affected Products : outlook_express- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2234
Buffer overflow in the getlvname command in IBM AIX 5.1, 5.2 and 5.3, might allow local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : aix- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2245
Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers.... Read more
Affected Products : tmos- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0564
Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.... Read more
Affected Products : word- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1219
Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.... Read more
Affected Products : image_color_management- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2220
Dragonfly Commerce allows remote attackers to change a product price by modifying the x_DragonflyCartProductPrice hidden field to (1) dc_Categorieslist.asp, (2) dc_Categoriesview.asp, (3) dc_productslist.asp, and (4) dc_productslist_Clearance.asp. NOTE: ... Read more
Affected Products : dragonfly_commerce- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2224
aspnet_wp.exe in Microsoft ASP.NET web services allows remote attackers to cause a denial of service (CPU consumption from infinite loop) via a crafted SOAP message to an RPC/Encoded method.... Read more
Affected Products : asp.net- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2225
Microsoft MSN Messenger allows remote attackers to cause a denial of service via a plaintext message containing the ".pif" string, which is interpreted as a malicious file extension and causes users to be kicked from a group conversation. NOTE: it has bee... Read more
Affected Products : msn_messenger_service- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2238
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.... Read more
Affected Products : aix- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2230
Electronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats temporary file insecurely, which allows local users to overwrite arbitrary files.... Read more
Affected Products : elmo- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2244
The aupair service (aupair.exe) in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to execute arbitrary code or corrupt memory via crafted packets that trigger a memo... Read more
Affected Products : call_manager- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2246
Multiple PHP remote file inclusion vulnerabilities in iPhotoAlbum 1.1 allow remote attackers to execute arbitrary code via the (1) doc_path parameter to getpage.php or (2) set_menu parameter to lib/static/header.php.... Read more
Affected Products : iphotoalbum- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2231
High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : heartbeat- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2241
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets, which results in a "resource leak" that allows remote a... Read more
Affected Products : call_manager- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2216
PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.... Read more
Affected Products : photogal_photo_gallery- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2237
Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : aix- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025