Latest CVE Feed
-
7.5
HIGHCVE-2005-1495
Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1501
MidiCart PHP Shopping Cart allows remote attackers to obtain sensitive information via a direct request to (1) search_list.php, (2) item_list.php, or (3) item_show.php, which reveal the path in a PHP error message.... Read more
Affected Products : midicart_php_shopping_cart- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1485
Golden FTP Server Pro 2.52 allows remote attackers to obtain sensitive information via a GET request for a file that does not exist, which reveals the absolute path of the FTP server in the resulting FTP error message.... Read more
Affected Products : golden_ftp_server- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1479
SQL injection vulnerability in jgs_portal.php in JGS-Portal 3.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : jgs-portal- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1490
Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists via the folder parameter to attachment.html.... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1497
index.php in myBloggie 2.1.1 allows remote attackers to obtain sensitive information via an invalid post_id parameter, which reveals the path in an error message.... Read more
Affected Products : mybloggie- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1478
Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiers in the xtellmail command.... Read more
Affected Products : dmail- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1482
ArticleLive 2005 allows remote attackers to gain privileges by modifying the (1) auth and (2) userId fields in a cookie.... Read more
Affected Products : articlelive- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1263
The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables funct... Read more
Affected Products : linux_kernel- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1515
Integer signedness error in the qmail_put and substdio_put functions in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large num... Read more
Affected Products : qmail- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2005-1513
Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request.... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1557
Multiple cross-site scripting (XSS) vulnerabilities in WebApp Guestbook PRO 3.2.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content of a message.... Read more
Affected Products : guestbook_pro- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1508
Multiple cross-site scripting (XSS) vulnerabilities in PwsPHP 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) month or (2) annee parameters to the news module, (3) nbractif or (4) annee parameters to the stats module, (5) i... Read more
Affected Products : pwsphp- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1499
delcomment.php in myBloggie 2.1.1 allows remote attackers to delete arbitrary comments by modifying the comment_id parameter.... Read more
Affected Products : mybloggie- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1484
Directory traversal vulnerability in Golden FTP server pro 2.52 allows remote attackers to read arbitrary files via a "\.." (backward slash dot dot) with a leading '"' (double quote) in the GET command.... Read more
Affected Products : golden_ftp_server- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1510
PwsPHP 1.2.2 allows remote attackers to obtain sensitive information via a direct request to the admin directory, which reveals the path in an error message.... Read more
Affected Products : pwsphp- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1486
Multiple cross-site scripting vulnerabilities in FishCart 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) trackingnum, (2) reqagree, or (3) m parameter to upstracking.php or (4) nlst parameter to display.php. NOTE: the vendo... Read more
Affected Products : fishcart- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1504
GameSpy SDK CD-Key Validation Toolkit, as used by many online games, allows remote attackers to bypass the CD key validation by sending a spoofed \disc\ command, which tells the server the CD key is no longer in use.... Read more
Affected Products : cd-key_validation_system- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1491
Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrary files via the importfile parameter to importaction.html.... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025
-
1.9
LOWCVE-2005-1488
Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) the E-mail address, Note, or Public Certificate fields to address.ht... Read more
- Published: May. 11, 2005
- Modified: Apr. 03, 2025