Latest CVE Feed
-
5.0
MEDIUMCVE-2005-0410
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.... Read more
Affected Products : citrusdb- Published: Feb. 14, 2005
- Modified: Apr. 03, 2025
-
5.5
MEDIUMCVE-2005-0406
A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.... Read more
Affected Products : image_processing- Published: Feb. 14, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0444
VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.... Read more
Affected Products : workstation- Published: Feb. 14, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-0409
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such as the pathnames for temporary files that store credit c... Read more
Affected Products : citrusdb- Published: Feb. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0430
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.... Read more
Affected Products : quake_3_engine- Published: Feb. 12, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0114
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort funct... Read more
- Published: Feb. 11, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0074
Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.... Read more
Affected Products : xpcd- Published: Feb. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0261
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.... Read more
Affected Products : aix- Published: Feb. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0364
Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.... Read more
Affected Products : hp-ux- Published: Feb. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0941
Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vu... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0362
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.... Read more
Affected Products : awstats- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0963
Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0957
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized acti... Read more
Affected Products : enterprise_linux enterprise_linux_desktop mysql suse_linux ubuntu_linux secure_linux openpkg- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0969
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0964
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0367
Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a .. (dot dot) in (1) the filename of an e-mail attachment, (2) the _msgatt.rec file, (3) and the ... Read more
Affected Products : argosoft_mail_server- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0939
changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entered, which allows remote attackers to guess passwords via... Read more
Affected Products : instant_virtual_extranet- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0972
The lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0978
Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData para... Read more
Affected Products : internet_explorer windows_2000 windows_server_2003 windows_xp windows_nt windows_98se windows_me- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0965
stmkfont in HP-UX B.11.00 through B.11.23 relies on the user-specified PATH when executing certain commands, which allows local users to execute arbitrary code by modifying the PATH environment variable to point to malicious programs.... Read more
Affected Products : hp-ux- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025