Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.1

    MEDIUM
    CVE-2005-0160

    Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.... Read more

    Affected Products : unace
    • EPSS Score: %2.19
    • Published: Feb. 22, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-0161

    Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.... Read more

    Affected Products : unace
    • EPSS Score: %0.46
    • Published: Feb. 22, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0535

    Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.... Read more

    Affected Products : mediawiki linux
    • EPSS Score: %0.87
    • Published: Feb. 22, 2005
    • Modified: Apr. 03, 2025
  • 1.2

    LOW
    CVE-2005-0937

    Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executin... Read more

    Affected Products : linux_kernel enterprise_linux
    • EPSS Score: %0.06
    • Published: Feb. 22, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-0503

    uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.... Read more

    Affected Products : mandrake_linux uim
    • EPSS Score: %0.07
    • Published: Feb. 21, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0494

    The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct ... Read more

    Affected Products : thomson_cable_modem
    • EPSS Score: %3.36
    • Published: Feb. 21, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0537

    Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.... Read more

    Affected Products : free_shopping_cart
    • EPSS Score: %0.49
    • Published: Feb. 21, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0511

    misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.... Read more

    Affected Products : vbulletin
    • EPSS Score: %82.75
    • Published: Feb. 21, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0467

    Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that cor... Read more

    Affected Products : putty
    • EPSS Score: %1.97
    • Published: Feb. 21, 2005
    • Modified: Apr. 03, 2025
  • 9.8

    CRITICAL
    CVE-2005-0496

    Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.... Read more

    Affected Products : network_backup
    • EPSS Score: %2.56
    • Published: Feb. 21, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0512

    PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulner... Read more

    Affected Products : mambo
    • EPSS Score: %0.75
    • Published: Feb. 21, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0499

    Gigafast router (aka CompUSA router) with the DNS proxy option enabled allows remote attackers to cause a denial of service via malformed DNS queries.... Read more

    Affected Products : gigafast_router
    • EPSS Score: %0.66
    • Published: Feb. 20, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-0092

    Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).... Read more

    • EPSS Score: %0.06
    • Published: Feb. 19, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0495

    Cross-site scripting (XSS) vulnerability in ZeroBoard allows remote attackers to inject arbitrary web script or HTML via the (1) sn1, (2) year, or (3) page parameter to zboard.php or (4) filename to view_image.php.... Read more

    Affected Products : zeroboard
    • EPSS Score: %0.34
    • Published: Feb. 19, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0513

    PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other versions including pMachine Free, allows remote attackers to execute arbitrary PHP code by directly requesting mail_autoc... Read more

    Affected Products : pmachine_pro
    • EPSS Score: %1.68
    • Published: Feb. 19, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0502

    Directory traversal vulnerability in Xinkaa 1.0.3 and earlier allows remote attackers to read arbitrary files via (1) ../ and (2) ..\ characters in an HTTP request.... Read more

    Affected Products : xinkaa_web_station
    • EPSS Score: %1.75
    • Published: Feb. 18, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-0242

    The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program directory, which is installed with weak default permissions... Read more

    Affected Products : messenger
    • EPSS Score: %0.06
    • Published: Feb. 18, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-0519

    ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability tha... Read more

    Affected Products : ftp_server
    • EPSS Score: %1.19
    • Published: Feb. 18, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0462

    Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.... Read more

    Affected Products : mercuryboard
    • EPSS Score: %0.30
    • Published: Feb. 17, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0243

    Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downloading and executing programs via file names containing ... Read more

    Affected Products : messenger
    • EPSS Score: %0.32
    • Published: Feb. 17, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 292485 Results