Latest CVE Feed
-
7.2
HIGHCVE-2005-2681
Unspecified vulnerability in the command line processing (CLI) logic in Cisco Intrusion Prevention System 5.0(1) and 5.0(2) allows local users with OPERATOR or VIEWER privileges to gain additional privileges via unknown vectors.... Read more
Affected Products : ips_sensor_software- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2650
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.... Read more
Affected Products : emefa_guestbook- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2637
Multiple SQL injection vulnerabilities in PHPFreeNews 1.40 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Match or (2) CatID parameter to SearchResults.php, or (3) the password to AccessControl.php.... Read more
Affected Products : phpfreenews- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2643
Tor 0.1.0.13 and earlier, and experimental versions 0.1.1.4-alpha and earlier, does not reject certain weak keys when using ephemeral Diffie-Hellman (DH) handshakes, which allows malicious Tor servers to obtain the keys that a client uses for other system... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2675
Note: the vendor has disputed this issue. Multiple SQL injection vulnerabilities in Land Down Under (LDU) 800 allow remote attackers to execute arbitrary SQL commands via the (1) s or (2) m parameter to forums.php, (3) o, (4) w, (5) s, or (6) p parameter ... Read more
Affected Products : land_down_under- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2459
The huft_build function in inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 returns the wrong value, which allows remote attackers to cause a denial of service (kernel crash) via a certain compressed file that leads to a null pointer der... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2458
inflate.c in the zlib routines in the Linux kernel before 2.6.12.5 allows remote attackers to cause a denial of service (kernel crash) via a compressed file with "improper tables".... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-2666
SSH, as implemented in OpenSSH before 4.0 and possibly other implementations, stores hostnames, IP addresses, and keys in plaintext in the known_hosts file, which makes it easier for an attacker that has compromised an SSH user's account to generate a lis... Read more
Affected Products : openssh- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2668
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2457
The driver for compressed ISO file systems (zisofs) in the Linux kernel before 2.6.12.5 allows local users and remote attackers to cause a denial of service (kernel crash) via a crafted compressed ISO file system.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-2646
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to cause a denial of service or read files via unknown vectors involving crafted HTTP reque... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2667
Unknown vulnerability in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows attackers to cause a denial of service via unknown vectors, aka the "CAM TCP port vulnerability."... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2647
Cross-site scripting (XSS) vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to inject arbitrary web script or HTML and modify web pages via unknown ... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2649
Cross-site scripting (XSS) vulnerability in ATutor 1.5.1 allows remote attackers to inject arbitrary web script or HTML via (1) course parameter in login.php or (2) words parameter in search.php.... Read more
Affected Products : atutor- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-0359
The Legato PortMapper in EMC Legato NetWorker, Sun Solstice Backup 6.0 and 6.1, and StorEdge Enterprise Backup 7.0 through 7.2 does not restrict access to the pmap_set and pmap_unset commands, which allows remote attackers to (1) cause a denial of service... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2653
Cross-site scripting (XSS) vulnerability in BBCaffe 2.0 allows remote attackers to inject arbitrary web script or HTML via e-mail data in a message.... Read more
Affected Products : bbcaffe- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2680
Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP4, when using entitlements, allows remote attackers to bypass access restrictions for the pages of a Book via crafted URLs.... Read more
Affected Products : weblogic_portal- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2651
gorum/prod.php in Zorum 3.5 allows remote attackers to execute arbitrary code via shell metacharacters in the argv parameter.... Read more
Affected Products : zorum- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2645
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to bypass authentication.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2631
Cisco Clean Access (CCA) 3.3.0 to 3.3.9, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3 does not properly authenticate users when invoking API methods, which could allow remote attackers to bypass security checks, change the assigned role of a user, or disconnect use... Read more
Affected Products : network_admission_control_manager_and_server_system_software- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025