Latest CVE Feed
-
4.6
MEDIUMCVE-2005-2291
Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information.... Read more
Affected Products : jdeveloper- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2280
Cisco Security Agent (CSA) 4.5 allows remote attackers to cause a denial of service (system crash) via a crafted IP packet.... Read more
Affected Products : security_agent- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2281
WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords.... Read more
Affected Products : webeoc- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2279
Cisco ONS 15216 Optical Add/Drop Multiplexer (OADM) running firmware 2.2.2 and earlier allows remote attackers to cause a denial of service (management plane session loss) via crafted telnet data.... Read more
Affected Products : ons_15216_optical_add_drop_multiplexer_software- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-2292
Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 stores cleartext passwords in (1) IDEConnections.xml, (2) XSQLConfig.xml and (3) settings.xml, which allows local users to obtain sensitive information.... Read more
Affected Products : jdeveloper- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-2278
Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.... Read more
Affected Products : mailenable_professional- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1175
Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.... Read more
Affected Products : kerberos_5- Published: Jul. 18, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2277
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.... Read more
Affected Products : affix- Published: Jul. 15, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2264
Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.... Read more
Affected Products : firefox- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-2262
Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascrip... Read more
Affected Products : firefox- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2248
Directory traversal vulnerability in DownloadProtect before 1.0.3 allows remote attackers to read files above the download folder.... Read more
Affected Products : downloadprotect- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2249
Multiple unknown vulnerabilities in Jinzora 2.0.1 have unknown impact and attack vectors, possibly involving a PHP file inclusion vulnerability.... Read more
Affected Products : jinzora- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2272
Safari version 2.0 (412) does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vuln... Read more
Affected Products : safari- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2267
Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to... Read more
Affected Products : firefox- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2263
The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes ... Read more
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2256
Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLanguage parameter.... Read more
Affected Products : phppgadmin- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2270
Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.... Read more
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2095
options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which allows remote attackers to modify or read the preferences of other users, conduct cross-site scripting XSS) attacks, and write arbitra... Read more
- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-2274
Microsoft Internet Explorer 6.0 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofi... Read more
Affected Products : internet_explorer- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2250
Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.... Read more
Affected Products : affix- Published: Jul. 13, 2005
- Modified: Apr. 03, 2025