Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 2.1

    LOW
    CVE-2005-0624

    reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.... Read more

    Affected Products : reportbug
    • Published: Feb. 28, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0603

    viewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing invalid regular expression syntax, which reveals the path in a PHP error message.... Read more

    Affected Products : phpbb
    • Published: Feb. 28, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0608

    Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.... Read more

    Affected Products : webmod
    • Published: Feb. 28, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-0579

    nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.... Read more

    Affected Products : freenx
    • Published: Feb. 25, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-0580

    cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.... Read more

    Affected Products : cmd5checkpw
    • Published: Feb. 25, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0107

    bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.... Read more

    Affected Products : bsmtpd
    • Published: Feb. 25, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0598

    The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.... Read more

    • Published: Feb. 24, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-0600

    Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.... Read more

    • Published: Feb. 24, 2005
    • Modified: Apr. 03, 2025
  • 4.6

    MEDIUM
    CVE-2005-0547

    Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."... Read more

    Affected Products : hp-ux
    • Published: Feb. 24, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0543

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no paramet... Read more

    Affected Products : phpmyadmin
    • Published: Feb. 24, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-0521

    SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.... Read more

    Affected Products : sendlink
    • Published: Feb. 23, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-0518

    eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.... Read more

    Affected Products : exeem
    • Published: Feb. 23, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2004-0481

    The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.... Read more

    Affected Products : solaris sunos
    • Published: Feb. 23, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-0516

    The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.... Read more

    Affected Products : imagegalleryplugin
    • Published: Feb. 23, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-0520

    ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.... Read more

    Affected Products : ftp_server
    • Published: Feb. 23, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-0517

    PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.... Read more

    Affected Products : peerftp_5
    • Published: Feb. 23, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0514

    Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.... Read more

    Affected Products : verity_ultraseek
    • Published: Feb. 22, 2005
    • Modified: Apr. 03, 2025
  • 1.2

    LOW
    CVE-2005-0937

    Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executin... Read more

    Affected Products : linux_kernel enterprise_linux
    • Published: Feb. 22, 2005
    • Modified: Apr. 03, 2025
  • 2.1

    LOW
    CVE-2005-0161

    Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.... Read more

    Affected Products : unace
    • Published: Feb. 22, 2005
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2005-0160

    Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.... Read more

    Affected Products : unace
    • Published: Feb. 22, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 292802 Results