Latest CVE Feed
-
7.5
HIGHCVE-2005-1391
Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP header.... Read more
Affected Products : pound- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1428
edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.... Read more
Affected Products : uphotogallery- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1438
PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.... Read more
Affected Products : osticket- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1416
Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.... Read more
Affected Products : 04webserver- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1433
Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.... Read more
Affected Products : openview_event_correlation_services- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1398
phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 through 4.6.4 are also affected.... Read more
Affected Products : phpcart- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1375
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) mo... Read more
Affected Products : claroline- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1381
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) cache_dump_file or (2) PartialPageErrorPage parameter.... Read more
- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1442
Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.... Read more
Affected Products : lotus_notes- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1413
Multiple SQL injection vulnerabilities in enVivo!CMS allow remote attackers to execute arbitrary SQL commands and gain privileges via the (1) username or (2) password parameters to admin_login.asp, or the (3) searchstring and possibly (4) ID parameters to... Read more
Affected Products : envivo_cms- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0157
The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.... Read more
Affected Products : smartlist- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1386
PHP-Nuke 7.6 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) ipban.php, (2) db.php, (3) lang-norwegian.php, (4) lang-indonesian.php, (5) lang-greek.php, (6) a request to Web_Links with the portuguese languag... Read more
Affected Products : php-nuke- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1436
Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php, (4)... Read more
Affected Products : osticket- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1427
Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.... Read more
Affected Products : uphotogallery- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-1423
Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.... Read more
Affected Products : 602lan_suite- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-1374
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php... Read more
Affected Products : claroline- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1826
Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension.... Read more
Affected Products : radia_client- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-1411
Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain privileges.... Read more
Affected Products : icuii- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1385
Safari 1.3 allows remote attackers to cause a denial of service (application crash) via a long https URL that triggers a NULL pointer dereference.... Read more
Affected Products : safari- Published: May. 03, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1431
The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.... Read more
- Published: May. 03, 2005
- Modified: Apr. 03, 2025