Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.8

    MEDIUM
    CVE-2005-3366

    PHP file inclusion vulnerability in index.php in PHP iCalendar 2.0a2 through 2.0.1 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the phpicalendar cookie. NOTE: this is not a cross-site scripting (XSS) issue a... Read more

    Affected Products : php_icalendar
    • Published: Oct. 30, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3382

    Multiple interpretation error in Sophos 3.91 with the 2.28.4 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be ... Read more

    Affected Products : sophos_anti-virus
    • Published: Oct. 30, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3385

    SQL injection vulnerability in Techno Dreams Mailing List script allows remote attackers to execute arbitrary SQL commands and bypass authentication via the userid parameter in admin/login.asp.... Read more

    Affected Products : mailing_list
    • Published: Oct. 30, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3364

    Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.... Read more

    Affected Products : dboardgear
    • Published: Oct. 30, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3365

    Multiple SQL injection vulnerabilities in DCP-Portal 6 and earlier allow remote attackers to execute arbitrary SQL commands, possibly requiring encoded characters, via (1) the name parameter in register.php, (2) the email parameter in lostpassword.php, (3... Read more

    Affected Products : dcp-portal
    • Published: Oct. 30, 2005
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2005-3378

    Multiple interpretation error in Norman 5.81 with the 5.83.02 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be... Read more

    Affected Products : norman_virus_control
    • Published: Oct. 30, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-3368

    Cross-site scripting (XSS) vulnerability in the Search_Enhanced module in PHP-Nuke 7.9 allows remote attackers to inject arbitrary web script or HTML via the query parameter.... Read more

    Affected Products : search_enhanced
    • Published: Oct. 30, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3381

    Multiple interpretation error in Ukrainian National Antivirus (UNA) 1.83.2.16 with kernel 265 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, wh... Read more

    Affected Products : una
    • Published: Oct. 30, 2005
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2005-3376

    Multiple interpretation error in Kaspersky 5.0.372 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe... Read more

    Affected Products : kaspersky_anti-virus
    • Published: Oct. 30, 2005
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2005-2930

    Stack-based buffer overflow in the _chm_find_in_PMGL function in chm_lib.c for chmlib before 0.36, as used in products such as KchmViewer, allows user-assisted attackers to execute arbitrary code via a CHM file containing a long element, a different vulne... Read more

    Affected Products : chm_lib
    • Published: Oct. 28, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-3361

    Cross-site scripting (XSS) vulnerability in forum/index.php in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the nome parameter in a login operation, a variant of CVE-2005-3306.... Read more

    Affected Products : flatnuke
    • Published: Oct. 28, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-2973

    The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash).... Read more

    Affected Products : linux_kernel
    • Published: Oct. 27, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3335

    PHP file inclusion vulnerability in bug_sponsorship_list_view_inc.php in Mantis 1.0.0RC2 and 0.19.2 allows remote attackers to execute arbitrary PHP code and include arbitrary local files via the t_core_path parameter.... Read more

    Affected Products : mantis
    • Published: Oct. 27, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-3334

    Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 p... Read more

    Affected Products : flyspray
    • Published: Oct. 27, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-3316

    The installation of ON Symantec Discovery 4.5.x and Symantec Discovery 6.0 creates the (1) DiscoveryWeb and (2) DiscoveryRO database accounts with null passwords, which could allow attackers to gain privileges or prevent Discovery from running by setting ... Read more

    Affected Products : discovery on_command_discovery
    • Published: Oct. 27, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-3331

    viewpatch in mgdiff 1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more

    Affected Products : mgdiff_patch_viewer
    • Published: Oct. 27, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-3247

    The SigComp UDVM in Ethereal 0.10.12 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.... Read more

    Affected Products : ethereal
    • Published: Oct. 27, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-3321

    chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating a hardlink to a file from a world-writable directory, which can cause the link count to drop to 1 when the file is deleted or replaced, which is then modi... Read more

    Affected Products : suse_linux suse_linux
    • Published: Oct. 27, 2005
    • Modified: Apr. 03, 2025
  • 9.3

    HIGH
    CVE-2005-3265

    Buffer overflow in Skype for Windows 1.1.x.0 through 1.4.x.83 allows remote attackers to execute arbitrary code via (1) callto:// and (2) skype:// links, or (3) a non-standard VCARD, possibly due to an underlying error in the SysUtils.WideFmtStr Delphi ro... Read more

    Affected Products : skype skype
    • Published: Oct. 27, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-3088

    fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.... Read more

    Affected Products : fetchmail
    • Published: Oct. 27, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 294837 Results