Latest CVE Feed
-
4.3
MEDIUMCVE-2005-3367
Cross-site scripting (XSS) vulnerability in journal.php in SparkleBlog 2.1 allows remote attackers to inject arbitrary web script or HTML via the name field.... Read more
Affected Products : sparkleblog- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3385
SQL injection vulnerability in Techno Dreams Mailing List script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.... Read more
Affected Products : mailing_list- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3374
Multiple interpretation error in F-Prot 3.16c allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type... Read more
Affected Products : f-prot_antivirus- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3386
SQL injection vulnerability in Techno Dreams Web Directory script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.... Read more
Affected Products : web_directory- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3368
Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more
Affected Products : search_enhanced- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3378
Multiple interpretation error in Norman 5.81 with the 5.83.02 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be... Read more
Affected Products : norman_virus_control- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-3377
Multiple interpretation error in (1) McAfee Internet Security Suite 7.1.5 version 9.1.08 with the 4.4.00 engine and (2) McAfee Corporate 8.0.0 patch 10 with the 4400 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and... Read more
Affected Products : internet_security_suite- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3365
Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name parameter in register.php, (2) the email parameter in lostpassword.php, (3... Read more
Affected Products : dcp-portal- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3363
SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to execute arbitrary SQL commands via the forumid parameter in (1) showcat.php and (2) add.php.... Read more
Affected Products : saphplesson- Published: Oct. 30, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-2930
Stack-based buffer overflow in the _chm_find_in_PMGL function in chm_lib.c for chmlib before 0.36, as used in products such as KchmViewer, allows user-assisted attackers to execute arbitrary code via a CHM file containing a long element, a different vulne... Read more
Affected Products : chm_lib- Published: Oct. 28, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3361
Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the nome parameter in a login operation, a variant of CVE-2005-3306.... Read more
Affected Products : flatnuke- Published: Oct. 28, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2973
The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash).... Read more
Affected Products : linux_kernel- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-3334
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 p... Read more
Affected Products : flyspray- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-3319
The apache2handler SAPI (sapi_apache2.c) in the Apache module (mod_php) for PHP 5.x before 5.1.0 final and 4.4 before 4.4.1 final allows attackers to cause a denial of service (segmentation fault) via the session.save_path option in a .htaccess file or Vi... Read more
Affected Products : php- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3325
Multiple SQL injection vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products... Read more
- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3242
Ethereal 0.10.12 and earlier allows remote attackers to cause a denial of service (crash) via unknown vectors in (1) the IrDA dissector and (2) the SMB dissector when SMB transaction payload reassembly is enabled.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-3339
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors.... Read more
Affected Products : mantis- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3243
Multiple buffer overflows in Ethereal 0.10.12 and earlier might allow remote attackers to execute arbitrary code via unknown vectors in the (1) SLIMP3 and (2) AgentX dissector.... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-3245
Unspecified vulnerability in the ONC RPC dissector in Ethereal 0.10.3 to 0.10.12, when the "Dissect unknown RPC program numbers" option is enabled, allows remote attackers to cause a denial of service (memory consumption).... Read more
Affected Products : ethereal- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-3327
Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation protocol, and uses Operational mode without proving identi... Read more
Affected Products : data_ontap- Published: Oct. 27, 2005
- Modified: Apr. 03, 2025