Latest CVE Feed
-
2.6
LOWCVE-2005-0145
Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.... Read more
Affected Products : firefox- Published: Jan. 24, 2005
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2005-0102
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.... Read more
- Published: Jan. 24, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0072
zhcon before 0.2 does not drop privileges before reading a user configuration file, which allows local users to read arbitrary files.... Read more
Affected Products : zhcon- Published: Jan. 24, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0103
PHP remote file inclusion vulnerability in webmail.php in SquirrelMail before 1.4.4 allows remote attackers to execute arbitrary PHP code by modifying a URL parameter to reference a URL on a remote web server that contains the code.... Read more
- Published: Jan. 24, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0193
Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.... Read more
Affected Products : mrouter- Published: Jan. 22, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0566
Buffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.... Read more
Affected Products : golden_ftp_server- Published: Jan. 22, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1057
Multiple drivers in Linux kernel 2.4.19 and earlier do not properly mark memory with the VM_IO flag, which causes incorrect reference counts and may lead to a denial of service (kernel panic) when accessing freed kernel pages.... Read more
- Published: Jan. 21, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1184
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.... Read more
- Published: Jan. 21, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1185
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.... Read more
Affected Products : enscript- Published: Jan. 21, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0300
Directory traversal vulnerability in session.php in JSBoard 2.0.9 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the table parameter.... Read more
Affected Products : jsboard- Published: Jan. 20, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1846
Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.... Read more
Affected Products : yamt- Published: Jan. 20, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1847
Multiple buffer overflows in YaMT before 0.5_2 allow attackers to execute arbitrary code via the (1) rename or (2) sort options.... Read more
Affected Products : yamt- Published: Jan. 20, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-0191
Off-by-one buffer overflow in the processing of tags in Real Metadata Package (RMP) files in RealPlayer 10.5 (6.0.12.1040) and earlier could allow remote attackers to execute arbitrary code via a long tag.... Read more
- Published: Jan. 19, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0186
Cisco IOS 12.1YD, 12.2T, 12.3 and 12.3T, when configured for the IOS Telephony Service (ITS), CallManager Express (CME) or Survivable Remote Site Telephony (SRST), allows remote attackers to cause a denial of service (device reboot) via a malformed packet... Read more
Affected Products : ios- Published: Jan. 19, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0116
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.... Read more
Affected Products : awstats- Published: Jan. 18, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0297
SQL injection vulnerability in Oracle Database 9i and 10g allows remote attackers to execute arbitrary SQL commands and gain privileges.... Read more
Affected Products : database_server- Published: Jan. 18, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0290
NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to bypass the filters using hex encoded URLs, as demonstrated using a hex encoded file extension.... Read more
Affected Products : fvs318- Published: Jan. 17, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0295
npptnt2.sys in nProtect Gameguard provides unrestricted I/O to any process that calls it, which allows local users to gain privileges.... Read more
Affected Products : nprotect_gameguard- Published: Jan. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0291
Cross-site scripting (XSS) vulnerability in the log viewer in NETGEAR FVS318 running firmware 2.4, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via a blocked URL phrase.... Read more
Affected Products : fvs318- Published: Jan. 17, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0221
Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.... Read more
Affected Products : gallery- Published: Jan. 17, 2005
- Modified: Apr. 03, 2025