Latest CVE Feed
-
4.6
MEDIUMCVE-2004-1181
htmlheadline before 21.8 allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : htmlheadline- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1174
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."... Read more
- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1090
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."... Read more
- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1091
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.... Read more
- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0812
Unknown vulnerability in the Linux kernel before 2.4.23, on the AMD AMD64 and Intel EM64T architectures, associated with "setting up TSS limits," allows local users to cause a denial of service (crash) and possibly execute arbitrary code.... Read more
- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1134
SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.... Read more
Affected Products : serendipity- Published: Apr. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1149
SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.... Read more
Affected Products : acnews- Published: Apr. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1301
nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files.... Read more
Affected Products : netizen- Published: Apr. 13, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1103
Sygate Security Agent (SSA) in Sygate Secure Enterprise 3.5 through 4.1 does not prevent the security policy from being updated by unprivileged users, which allows local users to modify the policy by exporting the policy file, changing it, and importing i... Read more
Affected Products : security_agent- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0790
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been... Read more
Affected Products : solaris windows_2000 windows_2003_server windows_xp sunos windows_98 windows_98se windows_me- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0562
GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.... Read more
Affected Products : msn_messenger- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0791
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack... Read more
- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1078
XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.... Read more
Affected Products : apache_distribution- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1130
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart allows remote attackers to inject arbitrary web script or HTML via the pg parameter.... Read more
Affected Products : pinnacle_cart- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1143
Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.... Read more
Affected Products : easyphpcalendar- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1145
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE... Read more
Affected Products : calendarscript- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1147
calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information.... Read more
Affected Products : calendarscript- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1071
SQL injection vulnerability in banner.inc.php in JPortal Web Portal 2.3.1 allows remote attackers to execute arbitrary SQL commands via the haslo parameter.... Read more
Affected Products : jportal_web_portal- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0610
Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files when p... Read more
Affected Products : freebsd- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0555
Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025