Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.0

    MEDIUM
    CVE-2005-1954

    singapore 0.9.11 allows remote attackers to obtain sensitive information via a direct request to (1) admin.class.php, (2) any .tpl.php file in templates/admin_default/, or (3) any .tpl.php file in templates/default/, which reveal the path in an error mess... Read more

    Affected Products : singapore
    • Published: Jun. 16, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1475

    The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.... Read more

    Affected Products : opera_browser
    • Published: Jun. 16, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-1962

    Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.... Read more

    Affected Products : cerberus_helpdesk
    • Published: Jun. 16, 2005
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2005-1973

    Java Web Start in Java 2 Platform Standard Edition (J2SE) 5.0 and 5.0 Update 1 allows applications to assign permissions to themselves and gain privileges.... Read more

    Affected Products : j2se
    • Published: Jun. 16, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1971

    Directory traversal vulnerability in InteractivePHP FusionBB .11 Beta and earlier allows remote attackers to include arbitrary local files via ".." sequences in the language parameter.... Read more

    Affected Products : fusionbb
    • Published: Jun. 16, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2026

    Enterasys Vertical Horizon VH-2402S before firmware 2.05.05.09 has a hard-coded account and password for debugging, which allows remote attackers to gain privileges.... Read more

    Affected Products : vertical_horizon-2402s
    • Published: Jun. 16, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2001

    Directory traversal vulnerability in pafiledb.php in paFileDB 3.1 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) in the action parameter.... Read more

    Affected Products : pafiledb
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1995

    Bitrix Site Manager 4.0.x allows remote attackers to obtain sensitive information via direct request to (1) subscr_form.php or (2) dbquery_error.php, which reveals the path in an error message.... Read more

    Affected Products : bitrix_site_manager
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1266

    Apache SpamAssassin 3.0.1, 3.0.2, and 3.0.3 allows remote attackers to cause a denial of service (CPU consumption and slowdown) via a message with a long Content-Type header without any boundaries.... Read more

    Affected Products : enterprise_linux spamassassin
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-1999

    Multiple cross-site scripting (XSS) vulnerabilities in pafiledb.php in paFileDB 3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby or (2) filelist parameters to the category action (category.php), or (3) pages parameter i... Read more

    Affected Products : pafiledb
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1997

    show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.... Read more

    Affected Products : mcgallery
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1998

    Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.... Read more

    Affected Products : mcgallery
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-1996

    PHP remote file inclusion vulnerability in start.php in Bitrix Site Manager 4.0.x allows remote attackers to execute arbitrary PHP code via the _SERVER[DOCUMENT_ROOT] parameter.... Read more

    Affected Products : bitrix_site_manager
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2002

    SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.... Read more

    Affected Products : mambo
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 5.0

    MEDIUM
    CVE-2005-2041

    Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE).... Read more

    Affected Products : virobot_linux_server
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-2000

    Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query ... Read more

    Affected Products : pafiledb
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1306

    The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."... Read more

    Affected Products : acrobat acrobat_reader
    • Published: Jun. 15, 2005
    • Modified: Apr. 03, 2025
  • 4.3

    MEDIUM
    CVE-2005-0563

    Cross-site scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA) component in Exchange Server 5.5 allows remote attackers to inject arbitrary web script or HTML via an email message with an encoded javascript: URL ("jav&#X41sc
ript:") ... Read more

    Affected Products : exchange_server
    • Published: Jun. 14, 2005
    • Modified: Apr. 03, 2025
  • 5.1

    MEDIUM
    CVE-2005-1211

    Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.... Read more

    Affected Products : internet_explorer
    • Published: Jun. 14, 2005
    • Modified: Apr. 03, 2025
  • 7.5

    HIGH
    CVE-2005-1206

    Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."... Read more

    • Published: Jun. 14, 2005
    • Modified: Apr. 03, 2025
Showing 20 of 294716 Results