Latest CVE Feed
-
7.5
HIGHCVE-2005-1711
Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected.... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1719
Unknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.... Read more
Affected Products : avast_antivirus- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1694
Multiple SQL injection vulnerabilities in Xanthia.php in the Xanthia module in PostNuke 0.750 allow remote attackers to execute arbitrary SQL commands via the (1) name or (2) module parameter.... Read more
Affected Products : postnuke- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1732
Cookie Cart allows remote attackers to read the Order Notification list via the testmycgi and path parameters to testmy.cgi.... Read more
Affected Products : cookie_cart- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1748
The embedded LDAP server in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 5, allows remote anonymous binds, which may allow remote attackers to view user entries or cause a denial of service.... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1693
Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, BrightStor ARCserve... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1695
Multiple cross-site scripting (XSS) vulnerabilities in the RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allow remote attackers to inject arbitrary web script or HTML via the (1) rss_url parameter to magpie_slashbox.php, or the url parameter to (2) ma... Read more
Affected Products : postnuke- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2005-1744
BEA WebLogic Server and WebLogic Express 7.0 through Service Pack 5 does not log out users when an application is redeployed, which allows those users to continue to access the application without having to log in again, which may be in violation of newly... Read more
Affected Products : weblogic_server- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1746
The cluster cookie parsing code in BEA WebLogic Server 7.0 through Service Pack 5 attempts to contact any host or port specified in a cookie, even when it is not in the cluster, which allows remote attackers to cause a denial of service (cluster slowdown)... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1713
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.... Read more
Affected Products : serendipity- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1707
The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.... Read more
Affected Products : linux_webapp-config- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1708
templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.... Read more
Affected Products : reporter- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1716
TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client IP addresses.... Read more
Affected Products : topo- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1749
Buffer overflow in BEA WebLogic Server and WebLogic Express 6.1 Service Pack 4 allows remote attackers to cause a denial of service (CPU consumption from thread looping).... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1742
BEA WebLogic Server and WebLogic Express 8.1 SP2 and SP3 allows users with the Monitor security role to "shrink or reset JDBC connection pools."... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1738
Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to "access files outside the home directory" and possibly execute arbitrary code via certain inputs that are not properly handled ... Read more
Affected Products : iron_bars_shell- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1733
Cookie Cart stores the password file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and encrypted passwords via a direct request to passwd.txt.... Read more
Affected Products : cookie_cart- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1734
Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : proms- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1737
Multiple unknown vulnerabilities in PROMS 0.11 allow "non-authorized users" to (1) view or modify the project member list or (2) modify the todos list.... Read more
Affected Products : proms- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1736
PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.... Read more
Affected Products : proms- Published: May. 24, 2005
- Modified: Apr. 03, 2025