Latest CVE Feed
-
7.5
HIGHCVE-2005-0668
Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files.... Read more
Affected Products : http_anti_virus_proxy_\(havp\)- Published: Mar. 04, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0674
Cross-site scripting (XSS) vulnerability in the News module for paBox 1.6 allows remote attackers to inject arbitrary web script or HTML via the text hidden parameter in an HTTP POST request.... Read more
Affected Products : pabox- Published: Mar. 03, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0671
Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a command.... Read more
Affected Products : ca3de- Published: Mar. 03, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0641
Cross-site scripting (XSS) vulnerability in the Reporter for Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 allows remote attackers to inject arbitrary HTML or web script via the (1) name or (2) description in a report template.... Read more
Affected Products : unicenter_asset_management- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0639
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.... Read more
- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0638
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.... Read more
- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0633
Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file.... Read more
- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0636
Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.... Read more
Affected Products : foxmail_email_server- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0620
Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local users to steal the information.... Read more
Affected Products : einstein- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0605
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop suse_linux propack mandrake_linux mandrake_linux_corporate_server fedora_core lesstif x11r6 x11r6 +1 more products- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0640
Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQL Admin password via certain methods.... Read more
Affected Products : unicenter_asset_management- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0622
RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.... Read more
Affected Products : raidenhttpd- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1002
Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0990
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1007
The quoted-printable decoder in bogofilter 0.17.4 to 0.92.7 allows remote attackers to cause a denial of service (application crash) via mail headers that cause a line feed (LF) to be replaced by a null byte that is written to an incorrect memory address.... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1032
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to delete arbitrary files or create arbitrary empty files via a target filename with a large number of leading slash (/) characters such that fcronsighup does not properly... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-1036
Cross-site scripting (XSS) vulnerability in the decoding of encoded text in certain headers in mime.php for SquirrelMail 1.4.3a and earlier, and 1.5.1-cvs before 23rd October 2004, allows remote attackers to execute arbitrary web script or HTML.... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2004-1055
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.6.0-pl2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PmaAbsoluteUri parameter, (2) the zero_rows parameter in read_dump.php, (3) the confirm form,... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1034
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header fo... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2004-1030
fcronsighup in Fcron 2.0.1, 2.9.4, and possibly earlier versions allows local users to gain sensitive information by calling fcronsighup with an arbitrary file, which reveals the contents of the file that can not be parsed in an error message.... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025