Latest CVE Feed
-
5.1
MEDIUMCVE-2005-0553
Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption V... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1245
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.2, when using HTML Tidy ($wgUseTidy), allows remote attackers to inject arbitrary web script or HTML via unknown vectors.... Read more
Affected Products : mediawiki- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1114
Multiple SQL injection vulnerabilities in album_search.php in Photo Album 2.0.53 for phpBB allow remote attackers to execute arbitrary SQL commands via the (1) mode or (2) search parameters.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0267
index.php in FlatNuke 2.5.1 allows remote attackers to create an administrator account via carriage returns and #10 in the url_avatar field, which is interpreted as a sensitive directive.... Read more
Affected Products : flatnuke- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0119
helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.... Read more
Affected Products : helvis- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2005-0061
The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0648
Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."... Read more
Affected Products : safehtml- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1083
index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.... Read more
Affected Products : aedating- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0435
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.... Read more
Affected Products : awstats- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
1.2
LOWCVE-2005-1368
The key_user_lookup function in security/keys/key.c in Linux kernel 2.6.10 to 2.6.11.8 may allow attackers to cause a denial of service (oops) via SMP.... Read more
Affected Products : linux_kernel- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1345
Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator.... Read more
Affected Products : squid- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1354
The forum.pl script allows remote attackers to execute arbitrary commands via shell metacharacters in the argument.... Read more
Affected Products : forum.pl- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1321
Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.... Read more
Affected Products : vaction- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1309
Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1319
Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.... Read more
Affected Products : imp- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1290
Multiple cross-site scripting (XSS) vulnerabilities in phpBB 2.0.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) u parameter to profile.php, (2) highlight parameter to viewtopic.php, or (3) forumname or forumdesc p... Read more
Affected Products : phpbb- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1327
Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid parameter.... Read more
Affected Products : burning_board- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
6.4
MEDIUMCVE-2005-0618
The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, when configured for load balancing between two WANs, migh... Read more
Affected Products : pro800turbo firewall_vpn_appliance_200r gateway_security_360 gateway_security_460- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0670
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML via (1) the new parameter to mod.php, (2) the w parameter to mod.php, (3) the e parameter to login.php, (4) the o param... Read more
Affected Products : phpcoin- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0644
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file with a type 2 header file name field, a variant of CVE-2005-0643.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025