Latest CVE Feed
-
1.9
LOWCVE-2005-1488
Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.ht... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1585
Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.... Read more
Affected Products : quick.forum- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1496
The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1494
Multiple cross-site scripting (XSS) vulnerabilities in admin.cgi in MegaBook 2.0 and 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) entryid or (2) password parameter.... Read more
Affected Products : megabook- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1493
Directory traversal vulnerability in SimpleCam 1.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URL.... Read more
Affected Products : simplecam- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1516
DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog command with an incorrect password hash, which is not properly handled by the _cmd_sendlog function.... Read more
Affected Products : dmail- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1262
Gaim 1.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed MSN message.... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-0039
Certain configurations of IPsec, when using Encapsulating Security Payload (ESP) in tunnel mode, integrity protection at a higher layer, or Authentication Header (AH), allow remote attackers to decrypt IPSec communications by modifying the outer packet in... Read more
Affected Products : ipsec- Published: May. 10, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1555
Cross-site scripting (XSS) vulnerability in the JRun Web Server in ColdFusion MX 7.0 allows remote attackers to inject arbitrary script or HTML via the URL, which is not properly quoted in the resulting default 404 error page.... Read more
Affected Products : coldfusion- Published: May. 10, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1477
The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combi... Read more
Affected Products : firefox- Published: May. 09, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-1476
Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.... Read more
Affected Products : firefox- Published: May. 09, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1399
FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.... Read more
Affected Products : freebsd- Published: May. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1471
Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.... Read more
Affected Products : securid_web_agent- Published: May. 06, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1400
The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.... Read more
Affected Products : freebsd- Published: May. 06, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1406
The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.... Read more
Affected Products : freebsd- Published: May. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1467
Unknown vulnerability in the NDPS dissector in Ethereal before 0.10.11 allows remote attackers to cause a denial of service (memory exhaustion) via unknown vectors.... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1468
Multiple unknown vulnerabilities in the (1) WSP, (2) Q.931, (3) H.245, (4) KINK, (5) MGCP, (6) RPC, (7) SMBMailslot, and (8) SMB NETLOGON dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (crash) via unknown vectors... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1469
Unknown vulnerability in the GSM dissector in Ethereal before 0.10.11 allows remote attackers to cause the dissector to access an invalid pointer.... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1463
Multiple format string vulnerabilities in the (1) DHCP and (2) ANSI A dissectors in Ethereal before 0.10.11 may allow remote attackers to execute arbitrary code.... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1460
Multiple unknown dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (assert error) via an invalid protocol tree item length.... Read more
- Published: May. 05, 2005
- Modified: Apr. 03, 2025