Latest CVE Feed
-
5.0
MEDIUMCVE-2005-1514
commands.c in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SMTP command without a space character, which causes an array ... Read more
Affected Products : qmail- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1588
SQL injection vulnerability in index.php for Quick.cart 0.3.0 allows remote attackers to execute arbitrary SQL commands via the iCategory parameter. NOTE: the vendor has privately disputed this issue, saying that Quick.cart does not even use SQL and ther... Read more
Affected Products : quick.cart- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1517
Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).... Read more
Affected Products : firewall_services_module- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1558
The web module in Neteyes Nexusway allows remote attackers to bypass authentication and gain administrator privileges by setting the cyclone500_auth cookie.... Read more
Affected Products : nexusway- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1489
Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certain requests to (1) calendar_addevent.html, (2) calendar_event.html, or (3) calendar_task.html.... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1487
Multiple SQL injection vulnerabilities in FishCart 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) cartid parameter to upstnt.php or (2) psku parameter to display.php. NOTE: the vendor disputes this report, saying that they are f... Read more
Affected Products : fishcart- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1555
Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.... Read more
Affected Products : coldfusion- Published: May. 10, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-0039
Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in... Read more
Affected Products : ipsec- Published: May. 10, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1476
Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.... Read more
Affected Products : firefox- Published: May. 09, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1477
The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combi... Read more
Affected Products : firefox- Published: May. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1471
Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.... Read more
Affected Products : securid_web_agent- Published: May. 06, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1399
FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.... Read more
Affected Products : freebsd- Published: May. 06, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1406
The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.... Read more
Affected Products : freebsd- Published: May. 06, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1400
The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.... Read more
Affected Products : freebsd- Published: May. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1462
Double free vulnerability in the ICEP dissector in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1459
Multiple unknown vulnerabilities in the (1) WSP, (2) BER, (3) SMB, (4) NDPS, (5) IAX2, (6) RADIUS, (7) TCAP, (8) MRDISC, (9) 802.3 Slow, (10) SMBMailslot, or (11) SMB PIPE dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of s... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1465
Unknown vulnerability in the NCP dissector in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (long loop).... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1464
Multiple unknown vulnerabilities in the (1) KINK, (2) L2TP, (3) MGCP, (4) EIGRP, (5) DLSw, (6) MEGACO, (7) LMP, and (8) RSVP dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (infinite loop).... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1453
fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other ser... Read more
Affected Products : leafnode- Published: May. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1458
Multiple unknown "other problems" in the KINK dissector in Ethereal before 0.10.11 have unknown impact and attack vectors.... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025