Latest CVE Feed
-
5.0
MEDIUMCVE-2005-2577
Wyse Winterm 1125SE running firmware 4.2.09f or 4.4.061f allows remote attackers to cause a denial of service (device crash) via a packet with a zero in the IP option length field.... Read more
Affected Products : winterm- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2566
Multiple SQL injection vulnerabilities in Open Bulletin Board (OpenBB) allow remote attackers to execute arbitrary SQL commands via the (1) FID parameter to board.php or (2) UID parameter to member.php.... Read more
Affected Products : openbb- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2579
Nortel Contivity VPN Client V05_01.030, when configuring a certificate to be used as authentication, does not properly drop system privileges, which allows local users to gain privileges by opening a program with the File Open dialog box.... Read more
Affected Products : contivity- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2570
FunkBoard 0.66CF, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to forums.php, which reveals the path in an error message.... Read more
Affected Products : funkboard- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2555
Linux kernel 2.6.x does not properly restrict socket policy access to users with the CAP_NET_ADMIN capability, which could allow local users to conduct unauthorized activities via (1) ipv4/ip_sockglue.c and (2) ipv6/ipv6_sockglue.c.... Read more
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2586
Mentor ADSL-FR4II router running firmware 2.00.0111 stores the web administration password in cleartext in the backup configuration file, which allows local users to obtain sensitive information.... Read more
Affected Products : adslfr4ii- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2102
The AIM/ICQ module in Gaim before 1.5.0 allows remote attackers to cause a denial of service (application crash) via a filename that contains invalid UTF-8 characters.... Read more
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2581
Grandstream BudgeTone 101 and 102 running firmware 1.0.6.7 and possibly earlier versions, allows remote attackers to cause a denial of service (device hang or reboot) via a large UDP packet to port 5060.... Read more
- Published: Aug. 16, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2498
Eval injection vulnerability in PHPXMLRPC 1.1.1 and earlier (PEAR XML-RPC for PHP), as used in multiple products including (1) Drupal, (2) phpAdsNew, (3) phpPgAds, and (4) phpgroupware, allows remote attackers to execute arbitrary PHP code via certain nes... Read more
- Published: Aug. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1527
Eval injection vulnerability in awstats.pl in AWStats 6.4 and earlier, when a URLPlugin is enabled, allows remote attackers to execute arbitrary Perl code via the HTTP Referrer, which is used in a $url parameter that is inserted into an eval function call... Read more
- Published: Aug. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2547
security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.... Read more
Affected Products : bluez- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2550
Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects... Read more
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2553
The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program... Read more
Affected Products : linux_kernel- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2549
Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list da... Read more
- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2548
vlan_dev.c in the VLAN code for Linux kernel 2.6.8 allows remote attackers to cause a denial of service (kernel oops from null dereference) via certain UDP packets that lead to a function call with the wrong argument, as demonstrated using snmpwalk on snm... Read more
Affected Products : linux_kernel- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2551
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.... Read more
Affected Products : edirectory- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2554
The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.... Read more
Affected Products : epolicy_orchestrator_agent- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2552
Unknown vulnerability in HP ProLiant DL585 servers running Integrated Lights Out (ILO) firmware before 1.81 allows attackers to access server controls when the server is "powered down."... Read more
Affected Products : proliant_dl585- Published: Aug. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2542
Invision Power Board (IPB) 1.0.3 allows remote attackers to inject arbitrary web script or HTML via an attachment, which is automatically downloaded and processed as HTML.... Read more
Affected Products : invision_board- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2537
FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to obtain sensitive information via a direct request to structure.php.... Read more
Affected Products : flatnuke- Published: Aug. 10, 2005
- Modified: Apr. 03, 2025