Latest CVE Feed
-
5.0
MEDIUMCVE-2005-0410
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.... Read more
Affected Products : citrusdb- Published: Feb. 14, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2005-0408
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating the MD5 checksum of the user name combined with the "boog... Read more
Affected Products : citrusdb- Published: Feb. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0411
Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.... Read more
Affected Products : citrusdb- Published: Feb. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0430
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.... Read more
Affected Products : quake_3_engine- Published: Feb. 12, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0074
Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.... Read more
Affected Products : xpcd- Published: Feb. 11, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0114
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort funct... Read more
- Published: Feb. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0364
Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.... Read more
Affected Products : hp-ux- Published: Feb. 10, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0261
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.... Read more
Affected Products : aix- Published: Feb. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0962
Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switch... Read more
Affected Products : apple_remote_desktop- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0982
Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL.... Read more
Affected Products : mpg123- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0950
NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when responses are disabled, a "custom" HELO request.... Read more
Affected Products : netop- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0966
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0976
Multiple scripts in the perl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.... Read more
Affected Products : perl- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0960
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-0967
The (1) pj-gs.sh, (2) ps2epsi, (3) pv.sh, and (4) sysvlp.sh scripts in the ESP Ghostscript (espgs) package in Trustix Secure Linux 1.5 through 2.1, and other operating systems, allow local users to overwrite files via a symlink attack on temporary files.... Read more
Affected Products : ghostscript- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-0970
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.... Read more
Affected Products : gzip- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0937
Sophos Anti-Virus before 3.87.0, and Sophos Anti-Virus for Windows 95, 98, and Me before 3.88.0, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compre... Read more
Affected Products : brightstor_arcserve_backup suse_linux etrust_ez_antivirus etrust_intrusion_detection kaspersky_anti-virus linux mandrake_linux etrust_secure_content_manager sophos_anti-virus etrust_antivirus +13 more products- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0963
Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-0957
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized acti... Read more
Affected Products : enterprise_linux enterprise_linux_desktop mysql suse_linux ubuntu_linux secure_linux openpkg- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025
-
7.8
HIGHCVE-2004-0940
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.... Read more
- Published: Feb. 09, 2005
- Modified: Apr. 03, 2025