Latest CVE Feed
-
7.2
HIGHCVE-2005-0385
Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a long -f command line argument.... Read more
Affected Products : luxman- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0022
Buffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the auth_spa_client function, may allow attackers to execute arbitrary code during SPA authentication.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0806
Evolution 2.0.3 allows remote attackers to cause a denial of service (application crash or hang) via crafted messages, possibly involving charsets in attachment filenames.... Read more
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-1063
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consumption) via certain attacks that force the product to "c... Read more
- Published: Apr. 29, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0414
SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.... Read more
Affected Products : mercuryboard- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0159
The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.... Read more
- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0087
The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.... Read more
- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0206
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.... Read more
Affected Products : enterprise_linux debian_linux enterprise_linux_desktop xpdf suse_linux linux xpdf gpdf kpdf ubuntu_linux +15 more products- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0229
CitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit card information via a direct request to newfile.txt.... Read more
Affected Products : citrusdb_customer_database- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-0412
Cross-site scripting (XSS) vulnerability in Spidean PostWrap allows remote attackers to inject arbitrary HTML and web script via the page parameter.... Read more
Affected Products : postwrap- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2005-0019
Unknown vulnerability in hztty 2.0 and earlier allows local users to execute arbitrary commands.... Read more
Affected Products : hztty- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0417
Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a dupli... Read more
Affected Products : db2_universal_database- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1488
wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.... Read more
Affected Products : wget- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0415
Multiple memory leaks in the MQL parser in Emdros before 1.1.22 allow remote attackers to cause a denial of service (memory consumption) via malformed MQL statements.... Read more
Affected Products : emdros_database_engine- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.8
MEDIUMCVE-2005-0420
Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.... Read more
Affected Products : exchange_server- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
6.8
MEDIUMCVE-2005-0085
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.... Read more
Affected Products : enterprise_linux suse_linux mandrake_linux mandrake_linux_corporate_server fedora_core htdig- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0424
Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.... Read more
Affected Products : aspjar_guestbook- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
2.1
LOWCVE-2005-0422
DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.... Read more
Affected Products : codebank- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0423
SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.... Read more
Affected Products : aspjar_guestbook- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0413
Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass par... Read more
Affected Products : myphp_forum- Published: Apr. 27, 2005
- Modified: Apr. 03, 2025