Latest CVE Feed
-
7.5
HIGHCVE-2005-0689
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the template parameter.... Read more
Affected Products : the_includer- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0701
Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via "\\.\\.." (modified dot dot backslash) sequences to UTL_FILE functions such as (1) UTL_FILE.FOPEN or (2) UTL_FILE.frename.... Read more
Affected Products : database_server- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0698
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH parameter to index.php to reference a URL on a remote web se... Read more
Affected Products : phpweblog- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0702
SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.... Read more
Affected Products : phpmyfaq- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0548
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.... Read more
- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0680
PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the c... Read more
Affected Products : download_center_lite- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0695
The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field.... Read more
Affected Products : hosting_controller- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0700
The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie.... Read more
Affected Products : aztek_forum- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-0667
Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to th... Read more
Affected Products : enterprise_linux sylpheed linux_advanced_workstation linux fedora_core alt_linux sylpheed-claws- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0179
Linux kernel 2.4.x and 2.6.x allows local users to cause a denial of service (CPU and memory consumption) and bypass RLIM_MEMLOCK limits via the mlockall call.... Read more
Affected Products : linux_kernel- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0694
Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.... Read more
Affected Products : hosting_controller- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0690
Gene6 FTP Server does not properly restrict access to the control console, which allows local users to modify the server configuration and gain privileges, as demonstrated by defining a SITE command.... Read more
Affected Products : g6_ftp_server- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0686
Integer overflow in mlterm 2.5.0 through 2.9.1, with gdk-pixbuf support enabled, allows remote attackers to execute arbitrary code via a large image file that is used as a background.... Read more
Affected Products : mlterm- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0697
SQL injection vulnerability in the process_picture function xp_publish.php in CopperExport 0.2.1 allows remote attackers to execute arbitrary SQL commands, possibly via the (1) title, (2) caption, or (3) keywords parameters.... Read more
Affected Products : copperexport- Published: Mar. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0691
PHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code by modifying the name parameter to reference a URL on a remote web server that contains the code.... Read more
Affected Products : socialmpn- Published: Mar. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0681
Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.... Read more
Affected Products : series- Published: Mar. 06, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0687
Format string vulnerability in Hashcash 1.16 allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via format string specifiers in a reply address, which is not properly handled when printing the hea... Read more
Affected Products : hashcash- Published: Mar. 06, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0692
Cross-site scripting (XSS) vulnerability in fusion_core.php for PHP-Fusion 5.x allows remote attackers to inject arbitrary web script or HTML via a message with IMG bbcode containing character-encoded Javascript.... Read more
Affected Products : php_fusion- Published: Mar. 06, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0688
Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the... Read more
- Published: Mar. 05, 2005
- Modified: Apr. 03, 2025
-
5.6
MEDIUMCVE-2005-0109
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensi... Read more
Affected Products : enterprise_linux enterprise_linux_desktop solaris freebsd unixware ubuntu_linux fedora_core openserver- Published: Mar. 05, 2005
- Modified: Apr. 03, 2025