Latest CVE Feed
-
7.2
HIGHCVE-2005-0113
inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.... Read more
Affected Products : irix- Published: Jan. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0111
Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.... Read more
Affected Products : maxdb- Published: Jan. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0381
Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.... Read more
Affected Products : forumkit- Published: Jan. 13, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0069
The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.... Read more
- Published: Jan. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0740
The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.... Read more
Affected Products : openbsd- Published: Jan. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0376
PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_la... Read more
Affected Products : sgallery- Published: Jan. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0456
Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.... Read more
Affected Products : opera_browser- Published: Jan. 12, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0117
Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.... Read more
Affected Products : xshisen- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-0288
The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.... Read more
Affected Products : webseries_payment_application- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0108
Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.... Read more
Affected Products : mod_auth_radius- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1039
The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a sepa... Read more
- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0897
The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0991
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.... Read more
- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0097
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.... Read more
Affected Products : squid- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1308
Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-b... Read more
Affected Products : libtiff- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1020
The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to read arbitrary files in PHP applications that contain a directory traversal vulnerability in require or include statements, but are ot... Read more
Affected Products : php- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0946
rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1160
Netscape 7.x to 7.2, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window o... Read more
Affected Products : navigator- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2004-1177
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0900
The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request ... Read more
Affected Products : windows_nt- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025