Latest CVE Feed
-
7.5
HIGHCVE-2004-1175
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.... Read more
- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0129
The Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%" variables, which are recursively expanded by the Server::parseWildcards function when the Part Button is selected.... Read more
Affected Products : konversation- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1174
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."... Read more
- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1091
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.... Read more
- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1181
htmlheadline before 21.8 allows local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
Affected Products : htmlheadline- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1090
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."... Read more
- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1005
Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.... Read more
- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1122
Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP GET request containing double-encoded format string specifiers (aka "double ... Read more
Affected Products : monkey- Published: Apr. 14, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1134
SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.... Read more
Affected Products : serendipity- Published: Apr. 13, 2005
- Modified: Apr. 03, 2025
-
2.6
LOWCVE-2005-1301
nProtect:Netizen 2005.3.17.1 does not properly verify that the update module is downloaded from an authorized site, which allows remote malicious web sites to write arbitrary files.... Read more
Affected Products : netizen- Published: Apr. 13, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1149
SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.... Read more
Affected Products : acnews- Published: Apr. 13, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1077
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.4.x allow remote attackers to inject arbitrary web script or HTML via (1) cds.php, (2) Guestbook-EN.pl, or (3) phonebook.php.... Read more
Affected Products : apache_distribution- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1145
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE... Read more
Affected Products : calendarscript- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1146
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different v... Read more
Affected Products : calendarscript- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-1099
Multiple buffer overflows in the HandleChild function in server.c in Greylisting daemon (GLD) 1.3 and 1.4, when GLD is listening on a network interface, allow remote attackers to execute arbitrary code.... Read more
Affected Products : gld- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0555
Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1143
Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.... Read more
Affected Products : easyphpcalendar- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0562
GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.... Read more
Affected Products : msn_messenger- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-1078
XAMPP 1.4.x has multiple default or null passwords, which allows attackers to gain privileges.... Read more
Affected Products : apache_distribution- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-1130
Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart allows remote attackers to inject arbitrary web script or HTML via the pg parameter.... Read more
Affected Products : pinnacle_cart- Published: Apr. 12, 2005
- Modified: Apr. 03, 2025