Latest CVE Feed
-
5.0
MEDIUMCVE-2005-0326
pafiledb.php in PaFileDB 3.1 allows remote attackers to gain sensitive information via an invalid or missing action parameter, which reveals the path in an error message when it cannot include a login.php script.... Read more
Affected Products : pafiledb- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0363
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.... Read more
Affected Products : awstats- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0397
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename a... Read more
Affected Products : imagemagick- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0438
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.... Read more
Affected Products : awstats- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0446
Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.... Read more
Affected Products : squid- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0525
The php_next_marker function in image.c for PHP 4.2.2, 4.3.9, 4.3.10 and 5.0.3, as reachable by the getimagesize PHP function, allows remote attackers to cause a denial of service (infinite loop) via a JPEG image with an invalid marker value, which causes... Read more
Affected Products : php- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0544
phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.php, (5) relation_cleanup.lib.php, (6) header_meta_style.i... Read more
Affected Products : phpmyadmin- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
6.2
MEDIUMCVE-2005-0602
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.... Read more
Affected Products : unzip- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.1
MEDIUMCVE-2005-0611
Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1325
set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.... Read more
Affected Products : phpmyvisites- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1278
The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.... Read more
Affected Products : tcpdump- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1235
auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.... Read more
Affected Products : phpbb-auction- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1224
Multiple SQL injection vulnerabilities in DUware DUportal Pro 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) nChannel parameter to default.asp, cat.asp, or detail.asp, (2) the iChannel parameter to search.asp, default.asp, result... Read more
Affected Products : duportal- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1359
Cross-site scripting (XSS) vulnerability in text.cgi script allows remote attackers to inject arbitrary web script or HTML via the argument.... Read more
Affected Products : text.cgi- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1293
Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQL commands via the (1) language, (2) bpic, (3) idcategory, (4) content, (5) keyword, or (6) idproduct parameter.... Read more
Affected Products : storeportal- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1353
The forum.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.... Read more
Affected Products : forum.pl- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1179
Unknown vulnerability in Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032, Pro 65/75/90 1.001.00.060 thro... Read more
Affected Products : workcentre workcentre_165 workcentre_175 workcentre_2128 workcentre_2636 workcentre_32_color workcentre_35 workcentre_3545 workcentre_40_color workcentre_45 +9 more products- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1164
Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game header that provides less data than indicated by the length.... Read more
Affected Products : yager_game- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0782
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the start parameter to pafiledb.php.... Read more
Affected Products : pafiledb- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1159
The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong ... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025