Latest CVE Feed
-
6.8
MEDIUMCVE-2005-0085
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.... Read more
Affected Products : enterprise_linux suse_linux mandrake_linux mandrake_linux_corporate_server fedora_core htdig- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1488
wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.... Read more
Affected Products : wget- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0159
The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0087
The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.... Read more
- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0229
CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.... Read more
Affected Products : citrusdb_customer_database- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0206
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_desktop xpdf suse_linux linux xpdf gpdf kpdf ubuntu_linux +15 more products- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0415
Multiple memory leaks in the MQL parser in Emdros before 1.1.22 allow remote attackers to cause a denial of service (memory consumption) via malformed MQL statements.... Read more
Affected Products : emdros_database_engine- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1487
wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.... Read more
Affected Products : wget- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1274
Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter.... Read more
Affected Products : maxdb- Published: Apr. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1281
Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.... Read more
- Published: Apr. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1270
The (1) check_update.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : rootkit_hunter- Published: Apr. 26, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0684
Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV fu... Read more
Affected Products : maxdb- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1298
The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.... Read more
Affected Products : inserter.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1300
Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.... Read more
Affected Products : inserter.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1275
Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.... Read more
- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1299
The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.... Read more
Affected Products : inserter.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1297
Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.... Read more
Affected Products : include.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1317
Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.... Read more
Affected Products : chora- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1295
include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.... Read more
Affected Products : include.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1296
include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.... Read more
Affected Products : include.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025