Latest CVE Feed
-
2.1
LOWCVE-2005-0156
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long direc... Read more
Affected Products : enterprise_linux aix enterprise_linux_desktop suse_linux perl ubuntu_linux propack fedora_core secure_linux- Published: Feb. 07, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0231
Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."... Read more
Affected Products : firefox- Published: Feb. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0100
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.... Read more
- Published: Feb. 07, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1131
Multiple buffer overflows in the enable command for SCO OpenServer 5.0.6 and 5.0.7 allow local users to execute arbitrary code via long command line arguments.... Read more
Affected Products : openserver- Published: Feb. 07, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0226
Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.... Read more
Affected Products : ngircd- Published: Feb. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0152
PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."... Read more
Affected Products : squirrelmail- Published: Feb. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0101
Buffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary code via a long string without a newline character.... Read more
Affected Products : newspost- Published: Feb. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0245
Buffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments to a refcursor function (gram.y), which leads to a heap-based buffer overflow, a different vulnerability than CVE-2005... Read more
Affected Products : postgresql- Published: Feb. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0224
Unknown vulnerability in HP-UX B.11.04 running Virtualvault 4.5 through 4.7, when running the TGA daemon, allows remote attackers to cause a denial of service via certain network traffic.... Read more
- Published: Jan. 31, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0075
prefs.php in SquirrelMail before 1.4.4, with register_globals enabled, allows remote attackers to inject local code into the SquirrelMail code via custom preference handlers.... Read more
- Published: Jan. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0104
Cross-site scripting (XSS) vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via certain integer variables.... Read more
- Published: Jan. 29, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0319
Direct remote injection vulnerability in modalfram.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to load external webpages that appear to come from the WebAdmin server, which allows remote attackers to inject arbitrary HTML or web script to facilita... Read more
Affected Products : webadmin- Published: Jan. 28, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0317
Cross-site scripting (XSS) vulnerability in useredit_account.wdm in Alt-N WebAdmin 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.... Read more
Affected Products : webadmin- Published: Jan. 28, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0316
WebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external systems, which could allow remote attackers to bypass intended access restrictions.... Read more
Affected Products : webwasher_classic- Published: Jan. 28, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0320
Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to login.html, (2) accountid parameter to accountsettings_add... Read more
Affected Products : web_mail- Published: Jan. 28, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0318
useredit_account.wdm in Alt-N WebAdmin 3.0.4 does not properly validate account edits by the logged in user, which allows remote authenticated users to edit other users' account information via a modified user parameter.... Read more
Affected Products : webadmin- Published: Jan. 28, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0312
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a for... Read more
Affected Products : war_ftp_daemon- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0891
Buffer overflow in the MSN protocol handler for gaim 0.79 to 1.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an "unexpected sequence of MSNSLP messages" that results in an unbounded co... Read more
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0882
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop samba ubuntu_linux linux_advanced_workstation linux fedora_core- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0889
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-20... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_desktop xpdf suse_linux xpdf gpdf kpdf ubuntu_linux linux_advanced_workstation +8 more products- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025