Latest CVE Feed
-
7.5
HIGHCVE-2005-1701
SQL injection vulnerability in PortailPHP 1.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to the (1) News, (2) File, (3) Liens, or (4) Faq modules.... Read more
Affected Products : portailphp- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1705
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.... Read more
Affected Products : gdb- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1715
Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5) field name, (6) Your Web field, or (7) email field in... Read more
Affected Products : topo- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1706
Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers to bypass virus detection.... Read more
Affected Products : mailscanner- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1747
Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 8.1 through Service Pack 4, and 7.0 through Service Pack 6, allow remote attackers to inject arbitrary web script or HTML, and possibly gain administrative privileges, ... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1737
Multiple unknown vulnerabilities in PROMS 0.11 allow "non-authorized users" to (1) view or modify the project member list or (2) modify the todos list.... Read more
Affected Products : proms- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1704
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section h... Read more
Affected Products : gdb- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1697
The RSS module in PostNuke 0.750 and 0.760RC2 and RC3 allows remote attackers to obtain sensitive information via a direct request to simple_smarty.php, which reveals the path in an error message.... Read more
Affected Products : postnuke- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1712
Unknown vulnerability in Serendipity 0.8, when used with multiple authors, allows unprivileged authors to upload arbitrary media files.... Read more
Affected Products : serendipity- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1702
Format string vulnerability in Warrior Kings: Battles 1.23 and earlier and Warrior Kings 1.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a nickname.... Read more
- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1708
templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.... Read more
Affected Products : reporter- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1707
The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.... Read more
Affected Products : linux_webapp-config- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1713
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.... Read more
Affected Products : serendipity- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1741
Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.... Read more
Affected Products : halo_combat_evolved- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1710
Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in t... Read more
Affected Products : reporter- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1703
Warrior Kings: Battles 1.23 and earlier allows remote attackers to cause a denial of service (server crash) via a partial join packet that triggers a NULL pointer dereference.... Read more
Affected Products : warrior_kings_battles- Published: May. 24, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1683
Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.... Read more
Affected Products : word- Published: May. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1687
SQL injection vulnerability in wp-trackback.php in Wordpress 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the tb_id parameter.... Read more
Affected Products : wordpress- Published: May. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1680
D-Link DSL-502T, DSL-504T, DSL-562T, and DSL-G604T, when /cgi-bin/firmwarecfg is executed, allows remote attackers to bypass authentication (1) if their IP address already exists in /var/tmp/fw_ip or (2) if their request is the first, which causes /var/tm... Read more
- Published: May. 20, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1676
Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allow remote attackers to inject arbitrary web script or HTM... Read more
- Published: May. 20, 2005
- Modified: Apr. 03, 2025