Latest CVE Feed
-
2.6
LOWCVE-2005-2534
Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients that use the same client certificate.... Read more
Affected Products : openvpn- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2686
Directory traversal vulnerability in SaveWebPortal 3.4 allows remote attackers to include arbitrary files and execute arbitrary local PHP programs via ".." sequences in the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.ph... Read more
Affected Products : savewebportal- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2532
OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client disconnection) via a large number of packets that can n... Read more
Affected Products : openvpn- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1842
VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, creates temporary log files with predictable names, which allows local users to modify arbitrary files via a syml... Read more
Affected Products : version_cue- Published: Aug. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0358
EMC Legato NetWorker, Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 6.0 through 7.2 do not properly verify authentication tokens, which allows remote attackers to gain privileges by modifying an authentication token.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2491
Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which lea... Read more
Affected Products : pcre- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2672
pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.... Read more
Affected Products : lm_sensors- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2674
Note: the vendor has disputed this issue. Multiple cross-site scripting (XSS) vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to inject arbitrary web script or HTML via the (1) c or (2) m parameters to index.php or (3) w parameter to j... Read more
Affected Products : land_down_under- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2633
Multiple PHP file inclusion vulnerabilities in (1) admin_o.php, (2) board_o.php, (3) dev_o.php, (4) file_o.php or (5) tech_o.php in PHPTB Topic Board 2.0 and earlier allow remote attackers to execute arbitrary PHP code via the absolutepath parameter.... Read more
Affected Products : topic_boards- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2652
Zorum 3.5 allows remote attackers to obtain the full installation path via direct requests to (1) gorum/notification.php, (2) user.php, (3) attach.php, (4) blacklist.php, (5) zorum/forum.php, (6) globalstat.php, (7) gorum/trace.php, (8) gorum/badwords.php... Read more
Affected Products : zorum- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2632
SQL injection vulnerability in login_admin_mediabox404.php in mediabox404 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the User field.... Read more
Affected Products : mediabox404- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2644
Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Jtext field.... Read more
Affected Products : jaguarcontrol- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2646
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to cause a denial of service or read files via unknown vectors involving crafted HTTP reque... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2639
Buffer overflow in Chris Moneymaker's World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname.... Read more
Affected Products : chris_moneymakers_world_poker_championship- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2634
Buffer overflow in the Log-SCR function in the "Log to Screen" feature in WinFtp Server 1.6.8 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long request.... Read more
Affected Products : winftp_server- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2638
Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) NewsMode parameter to NewsCategoryForm.php, or the (2) Match or (3) NewsMode parameter to SearchR... Read more
Affected Products : phpfreenews- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2499
slocate before 2.7 does not properly process very long paths, which allows local users to cause a denial of service (updatedb exit and incomplete slocate database) via a certain crafted directory structure.... Read more
Affected Products : slocate- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2635
Multiple directory traversal vulnerabilities in phpAdsNew and phpPgAds before 2.0.6 allow remote attackers to include arbitrary files via a .. (dot dot) in the (1) layerstyle parameter to adlayer.php or (2) language parameter to js-form.php.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2099
The Linux kernel before 2.6.12.5 does not properly destroy a keyring that is not instantiated properly, which allows local users or remote attackers to cause a denial of service (kernel oops) via a keyring with a payload that is not empty, which causes th... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2098
The KEYCTL_JOIN_SESSION_KEYRING operation in the Linux kernel before 2.6.12.5 contains an error path that does not properly release the session management semaphore, which allows local users or remote attackers to cause a denial of service (semaphore hang... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025