Latest CVE Feed
-
5.0
MEDIUMCVE-2005-1386
PHP-Nuke 7.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) ipban.php, (2) db.php, (3) lang-norwegian.php, (4) lang-indonesian.php, (5) lang-greek.php, (6) a request to Web_Links with the portuguese languag... Read more
Affected Products : php-nuke- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1381
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.... Read more
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0157
The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.... Read more
Affected Products : smartlist- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1441
Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).... Read more
Affected Products : lotus_domino- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0106
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.... Read more
Affected Products : ubuntu_linux- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-1343
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.... Read more
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-1410
The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a de... Read more
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1409
PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."... Read more
Affected Products : postgresql- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1397
SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.... Read more
Affected Products : php-calendar- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1384
Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to index.php, (2) phpcoinsessid parameter to login.php, (3) id, (4) dtopic_id, or (5) dcat_id to mod.php.... Read more
Affected Products : phpcoin- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1443
Multiple cross-site scripting (XSS) vulnerabilities in index.php for Invision Power Board (IPB) 2.0.3 and 2.1 Alpha 2 allows remote attackers to inject arbitrary web script or HTML via the (1) act, (2) Members, (3) calendar, or (4) HID parameters.... Read more
Affected Products : invision_power_board- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1379
The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs the mpi user without a password, which allows local users to gain privileges.... Read more
Affected Products : mandrake_lam-runtime- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1435
Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.... Read more
Affected Products : open_webmail- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1415
Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a long FTP command.... Read more
Affected Products : secure_ftp_server- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1825
Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameter... Read more
Affected Products : radia_client- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1372
nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.... Read more
Affected Products : netvault- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1378
SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.... Read more
Affected Products : phpbb_personal_notes_module- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1446
SitePanel 2.6.1 and earlier (SitePanel2) allows remote attackers to upload and execute arbitrary files such as PHP scripts via an attachment to a trouble ticket.... Read more
Affected Products : sitepanel- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1370
Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.... Read more
Affected Products : openview_radia_management_portal- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1426
Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).... Read more
Affected Products : ublog- Published: May. 03, 2005
- Modified: Apr. 03, 2025