Latest CVE Feed
-
4.3
MEDIUMCVE-2005-2094
Sun SunONE web server 6.1 SP1 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which cause... Read more
Affected Products : one_web_server- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2086
PHP remote file inclusion vulnerability in viewtopic.php in phpBB 2.0.15 and earlier allows remote attackers to execute arbitrary PHP code.... Read more
Affected Products : phpbb- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2081
Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.... Read more
Affected Products : asterisk- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2108
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file.... Read more
Affected Products : wordpress- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2088
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Enc... Read more
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2085
Buffer overflow in Inframail Advantage Server Edition 6.0 through 6.7 allows remote attackers to cause a denial of service (process crash) via a long (1) SMTP FROM field or possibly (2) FTP NLST command.... Read more
Affected Products : inframail_advantage- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-2145
The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an "allow" message to bypass a warning message.... Read more
Affected Products : prevx_pro_2005- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2135
SQL injection vulnerability in verify.asp in EtoShop Dynamic Biz Website Builder (QuickWeb) 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) T1 or (2) T2 parameters.... Read more
Affected Products : dynamic_biz_website_builder_quickweb- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2115
Soldier of Fortune II 1.02x and 1.03 allows remote attackers to cause a denial of service (server crash) via a large ID value in the ignore command, which is used as an array index and causes an out-of-bounds operation.... Read more
Affected Products : soldier_of_fortune_2- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2110
WordPress 1.5.1.2 and earlier allows remote attackers to obtain sensitive information via (1) a direct request to menu-header.php or a "1" value in the feed parameter to (2) wp-atom.php, (3) wp-rss.php, or (4) wp-rss2.php, which reveal the path in an erro... Read more
Affected Products : wordpress- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-2111
login.cgi in Community Link Pro Web Editor allows remote attackers to execute arbitrary commands via the file parameter.... Read more
Affected Products : community_link_pro_web_editor- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1921
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch... Read more
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2083
Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.... Read more
Affected Products : ia_emailserver- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-2114
Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty func... Read more
- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1625
Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 for Unix allows remote attackers to execute arbitrary code via a PDF document with a long /Filespec tag.... Read more
Affected Products : acrobat_reader- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1931
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command with an invalid argument, as demonstrated using an "A" character.... Read more
Affected Products : goodtech_smtp_server- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1917
kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.... Read more
Affected Products : kpopper- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2090
Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and ... Read more
Affected Products : tomcat- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2138
Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.... Read more
Affected Products : comdev_ecommerce- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-2089
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes II... Read more
Affected Products : internet_information_services- Published: Jul. 05, 2005
- Modified: Apr. 03, 2025