Latest CVE Feed
-
4.6
MEDIUMCVE-2005-0640
Computer Associates (CA) Unicenter Asset Management (UAM) 4.0 does not properly initialize the "Change Credentials for Database" window, which allows local users to recover the SQL Admin password via certain methods.... Read more
Affected Products : unicenter_asset_management- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0605
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.... Read more
Affected Products : enterprise_linux enterprise_linux_desktop suse_linux propack mandrake_linux mandrake_linux_corporate_server fedora_core lesstif x11r6 x11r6 +1 more products- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0639
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer overflows in PPM files.... Read more
- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0638
xloadimage before 4.1-r2, and xli before 1.17, allows attackers to execute arbitrary commands via shell metacharacters in filenames for compressed images, which are not properly quoted when calling the gunzip command.... Read more
- Published: Mar. 02, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1003
Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability via the smency.nsf file.... Read more
Affected Products : scanmail_domino- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
4.6
MEDIUMCVE-2004-1001
Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled.... Read more
Affected Products : shadow- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0989
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL ... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1052
Buffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an IRC server response that contains many (1) ! (exclamation) or (2) @ (at sign) characters.... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-0988
Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation.... Read more
Affected Products : quicktime- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
7.2
HIGHCVE-2004-1038
A design error in the IEEE1394 specification allows attackers with physical access to a device to read and write to sensitive memory using a modified FireWire/IEEE 1394 client, thus bypassing intended restrictions that would normally require greater degre... Read more
Affected Products : firewire_ieee- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1037
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-1021
iCal before 1.5.4 on Mac OS X 10.2.3, and other later versions, does not alert the user when handling calendars that use alarms, which allows attackers to execute programs and send e-mail via alarms.... Read more
Affected Products : ical- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2004-1027
Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2004-0986
Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0992
Format string vulnerability in the -a option (daemon mode) in Proxytunnel before 1.2.3 allows remote attackers to execute arbitrary code via format string specifiers in an invalid proxy answer.... Read more
Affected Products : proxytunnel- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0622
RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.... Read more
Affected Products : raidenhttpd- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1034
Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header fo... Read more
- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
4.3
MEDIUMCVE-2005-0628
Multiple cross-site scripting (XSS) vulnerabilities in Forumwa 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter in search.php or the (2) body or (3) subject of a forum message.... Read more
Affected Products : forumwa- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
7.5
HIGHCVE-2005-0623
Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.... Read more
Affected Products : raidenhttpd- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
5.0
MEDIUMCVE-2005-0632
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter.... Read more
Affected Products : phpnews- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025