Latest CVE Feed
-
7.5
HIGHCVE-2005-1822
Multiple SQL injection vulnerabilities in Qualiteam X-Cart 4.0.8 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) printable parameter to home.php, (3) productid or (4) mode parameter to product.php, (5) id parameter to error... Read more
Affected Products : x-cart- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1835
NEXTWEB (i)Site stores databases under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to databases/Users.mdb.... Read more
Affected Products : nextweb_\(i\)site- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1815
Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of dat... Read more
Affected Products : connectivity- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1820
zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function.... Read more
Affected Products : zeroboard- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1790
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismat... Read more
Affected Products : internet_explorer- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2005-1813
Directory traversal vulnerability in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allows remote attackers to read arbitrary files via a TFTP GET request containing (1) "../" (dot dot slash) or (2) "..\" (dot dot backslash) sequences.... Read more
Affected Products : tftp_server_2000- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1793
User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.... Read more
Affected Products : windows_98se- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1836
NEXTWEB (i)Site allows remote attackers to cause a denial of service (error 500) via a crafted HTTP request, possibly involving wildcard requests for .jsp files.... Read more
Affected Products : nextweb_\(i\)site- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1818
Multiple SQL injection vulnerabilities in NewLife Blogger before 3.3.1 allow remote attackers to execute arbitrary SQL commands via unknown attack vectors.... Read more
Affected Products : newlife_blogger- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1792
Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache.... Read more
Affected Products : windows_xp- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1814
Stack-based buffer overflow in PicoWebServer 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URL.... Read more
Affected Products : picowebserver- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1834
SQL injection vulnerability in login.asp in NEXTWEB (i)Site allows remote attackers to execute arbitrary SQL commands and bypass authentication via the password field.... Read more
Affected Products : nextweb_\(i\)site- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1812
Multiple stack-based buffer overflows in FutureSoft TFTP Server Evaluation Version 1.0.0.1 allow remote attackers to execute arbitrary code via a long (1) filename or (2) transfer mode string in a Read Request (RRQ) or Write Request (WRQ) packet.... Read more
Affected Products : tftp_server_2000- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1788
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.... Read more
Affected Products : hosting_controller- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1816
Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen.... Read more
Affected Products : invision_board- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1817
Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.... Read more
Affected Products : invision_board- Published: Jun. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1774
WEB-DAV Linux File System (davfs2) 0.2.3 does not properly enforce Unix permissions, which allows local users to write arbitrary files on a davfs2 mounted filesystem.... Read more
Affected Products : davfs2- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1785
SQL injection vulnerability in ad/login.asp in ZonGG 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.... Read more
Affected Products : zongg- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1796
Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code.... Read more
- Published: May. 31, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1866
Cross-site scripting (XSS) vulnerability in calendar.php in Calendarix Advanced 1.5 allows remote attackers to inject arbitrary web script or HTML via the year parameter.... Read more
Affected Products : calendarix_advanced- Published: May. 31, 2005
- Modified: Apr. 03, 2025