Latest CVE Feed
-
2.1
LOWCVE-2005-0580
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.... Read more
Affected Products : cmd5checkpw- Published: Feb. 25, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0107
bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.... Read more
Affected Products : bsmtpd- Published: Feb. 25, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0579
nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.... Read more
Affected Products : freenx- Published: Feb. 25, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0600
Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.... Read more
Affected Products : application_and_content_networking_software content_delivery_manager content_distribution_manager_4630 content_distribution_manager_4650 content_distribution_manager_4670 content_engine content_engine_module_for_cisco_router enterprise_content_delivery_network_software content_router_4430 content_router_4450- Published: Feb. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0547
Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."... Read more
Affected Products : hp-ux- Published: Feb. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0543
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no paramet... Read more
Affected Products : phpmyadmin- Published: Feb. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0598
The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.... Read more
Affected Products : application_and_content_networking_software content_delivery_manager content_distribution_manager_4630 content_distribution_manager_4650 content_distribution_manager_4670 content_engine content_engine_module_for_cisco_router enterprise_content_delivery_network_software content_router_4430 content_router_4450- Published: Feb. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0516
The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.... Read more
Affected Products : imagegalleryplugin- Published: Feb. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0517
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.... Read more
Affected Products : peerftp_5- Published: Feb. 23, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0520
ArGoSoft FTP Server before 1.4.2.8 allows remote attackers to read arbitrary files via shortcut (.LNK) files in the SITE COPY command, a different vulnerability than CVE-2005-0519.... Read more
Affected Products : ftp_server- Published: Feb. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0521
SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.... Read more
Affected Products : sendlink- Published: Feb. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0481
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.... Read more
- Published: Feb. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0518
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.... Read more
Affected Products : exeem- Published: Feb. 23, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0161
Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.... Read more
Affected Products : unace- Published: Feb. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0535
Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.... Read more
- Published: Feb. 22, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-0937
Some futex functions in futex.c for Linux kernel 2.6.x perform get_user calls while holding the mmap_sem semaphore, which could allow local users to cause a deadlock condition in do_page_fault by triggering get_user faults while another thread is executin... Read more
- Published: Feb. 22, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0514
Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.... Read more
Affected Products : verity_ultraseek- Published: Feb. 22, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-0160
Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" messages.... Read more
Affected Products : unace- Published: Feb. 22, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2005-0496
Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.... Read more
Affected Products : network_backup- Published: Feb. 21, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0511
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.... Read more
Affected Products : vbulletin- Published: Feb. 21, 2005
- Modified: Apr. 03, 2025