Latest CVE Feed
-
5.0
MEDIUMCVE-2005-0095
The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cach... Read more
Affected Products : squid- Published: Jan. 15, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0094
Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.... Read more
Affected Products : squid- Published: Jan. 15, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-0110
Internet Explorer 6 on Windows XP SP2 allows remote attackers to bypass the file download warning dialog and possibly trick an unknowledgeable user into executing arbitrary code via a web page with a body element containing an onclick tag, as demonstrated... Read more
- Published: Jan. 14, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0113
inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.... Read more
Affected Products : irix- Published: Jan. 14, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0069
The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.... Read more
- Published: Jan. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0111
Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.... Read more
Affected Products : maxdb- Published: Jan. 13, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0740
The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.... Read more
Affected Products : openbsd- Published: Jan. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0381
Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.... Read more
Affected Products : forumkit- Published: Jan. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0376
PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_la... Read more
Affected Products : sgallery- Published: Jan. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0456
Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.... Read more
Affected Products : opera_browser- Published: Jan. 12, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1039
The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a sepa... Read more
- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0117
Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.... Read more
Affected Products : xshisen- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
3.6
LOWCVE-2005-0288
The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.... Read more
Affected Products : webseries_payment_application- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0991
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.... Read more
- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0897
The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0108
Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.... Read more
Affected Products : mod_auth_radius- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0097
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.... Read more
Affected Products : squid- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1165
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using ... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1070
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive m... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2004-1125
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and poss... Read more
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025