Latest CVE Feed
-
7.2
HIGHCVE-2005-1151
qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.... Read more
- Published: May. 25, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1748
The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1749
Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1712
Unknown vulnerability in Serendipity 0.8, when used with multiple authors, allows unprivileged authors to upload arbitrary media files.... Read more
Affected Products : serendipity- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1734
Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : proms- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1702
Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname.... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1733
Cookie Cart stores the password file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and encrypted passwords via a direct request to passwd.txt.... Read more
Affected Products : cookie_cart- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1697
The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.... Read more
Affected Products : postnuke- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1738
Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to "access files outside the home directory" and possibly execute arbitrary code via certain inputs that are not properly handled ... Read more
Affected Products : iron_bars_shell- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1742
BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2005-1744
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly... Read more
Affected Products : weblogic_server- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1741
Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.... Read more
Affected Products : halo_combat_evolved- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1703
Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a NULL pointer dereference.... Read more
Affected Products : warrior_kings_battles- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1710
Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in t... Read more
Affected Products : reporter- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1717
ZyXEL Prestige 650R-31 router running ZyNOS FW v3.40(KO.1) allows remote attackers to cause a denial of service (CPU consumption and network loss) via crafted fragmented IP packets.... Read more
Affected Products : prestige_650r-31- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1735
Multiple cross-site scripting (XSS) vulnerabilities in PROMS before 0.11 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : proms- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1709
Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.... Read more
Affected Products : reporter- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1745
The UserLogin control in BEA WebLogic Portal 8.1 through Service Pack 3 prints the password to standard output when an incorrect login attempt is made, which could make it easier for attackers to guess the correct password.... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.0
MEDIUMCVE-2005-1699
Directory traversal vulnerability in pnadminapi.php in the Xanthia module in PostNuke 0.760-RC3 allows remote administrators to read arbitrary files via a .. (dot dot) in the skin parameter.... Read more
Affected Products : postnuke- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1692
Format string vulnerability in gxine 0.4.1 through 0.4.4, and other versions down to 0.3, allows remote attackers to execute arbitrary code via a ram file with a URL whose hostname contains format string specifiers.... Read more
Affected Products : gxine- Published: May. 24, 2005
- Modified: Apr. 03, 2025