Latest CVE Feed
-
10.0
HIGHCVE-2005-0417
Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a dupli... Read more
Affected Products : db2_universal_database- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-0412
Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter.... Read more
Affected Products : postwrap- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0019
Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.... Read more
Affected Products : hztty- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1342
CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.... Read more
Affected Products : cvs- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1274
Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a long "If" parameter.... Read more
Affected Products : maxdb- Published: Apr. 26, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1270
The (1) check_update.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.... Read more
Affected Products : rootkit_hunter- Published: Apr. 26, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1281
Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.... Read more
- Published: Apr. 26, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1299
The inserter.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.... Read more
Affected Products : inserter.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1317
Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.... Read more
Affected Products : chora- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1297
Cross-site scripting (XSS) vulnerability in the include.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.... Read more
Affected Products : include.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1275
Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.... Read more
- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1296
include.cgi script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.... Read more
Affected Products : include.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1300
Cross-site scripting (XSS) vulnerability in the inserter.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.... Read more
Affected Products : inserter.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1298
The inserter.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.... Read more
Affected Products : inserter.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0684
Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV fu... Read more
Affected Products : maxdb- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1295
include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.... Read more
Affected Products : include.cgi- Published: Apr. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1303
The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.... Read more
Affected Products : citat.pl- Published: Apr. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1312
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.... Read more
Affected Products : yappa-ng- Published: Apr. 24, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1294
The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.... Read more
Affected Products : affix- Published: Apr. 24, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1246
Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format string specifiers that are not properly handled in a syslog c... Read more
Affected Products : snmppd- Published: Apr. 24, 2005
- Modified: Apr. 03, 2025