273601
|
7.5 |
HIGH
|
apple
|
mac_os_x_server
|
Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
|
NVD-CWE-Other
|
CVE-2005-2507
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273602
|
4.6 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.
|
NVD-CWE-Other
|
CVE-2005-2508
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273603
|
2.1 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accoun…
|
NVD-CWE-Other
|
CVE-2005-2509
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273604
|
4.6 |
MEDIUM
|
apple
|
mac_os_x_server
|
The Server Admin tool in servermgr_ipfilter for Mac OS X 10.4 to 10.4.2, when using multiple subnets and Address Groups, does not always properly write firewall rules to the Active Rules when certain…
|
NVD-CWE-Other
|
CVE-2005-2510
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273605
|
10.0 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in Mac OS X 10.4.2 and earlier, when using Kerberos authentication with LDAP, allows attackers to gain access to a root Terminal window.
|
NVD-CWE-Other
|
CVE-2005-2511
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273606
|
2.1 |
LOW
|
apple
|
mail mac_os_x
|
Mail.app in Mac OS 10.4.2 and earlier, when printing or forwarding an HTML message, loads remote images even when the user's preferences state otherwise, which could result in a privacy leak.
|
NVD-CWE-Other
|
CVE-2005-2512
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273607
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure input fields.
|
NVD-CWE-Other
|
CVE-2005-2513
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273608
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-2514
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273609
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Quartz Composer Screen Saver in Mac OS X 10.4.2 allows local users to access links from the RSS Visualizer even when a password is required.
|
NVD-CWE-Other
|
CVE-2005-2515
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273610
|
7.5 |
HIGH
|
apple
|
safari mac_os_x
|
Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arb…
|
NVD-CWE-Other
|
CVE-2005-2516
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273611
|
2.6 |
LOW
|
apple
|
safari mac_os_x
|
Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site.
|
NVD-CWE-Other
|
CVE-2005-2517
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273612
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Buffer overflow in servermgrd in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
|
NVD-CWE-Other
|
CVE-2005-2518
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273613
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
slpd in Directory Services in Mac OS X 10.3.9 creates insecure temporary files as root, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2519
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273614
|
2.1 |
LOW
|
apple
|
mac_os_x
|
The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allow…
|
NVD-CWE-Other
|
CVE-2005-2520
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273615
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-2521
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273616
|
5.1 |
MEDIUM
|
apple
|
safari mac_os_x
|
Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file.
|
NVD-CWE-Other
|
CVE-2005-2522
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273617
|
4.3 |
MEDIUM
|
apple
|
weblog_server mac_os_x
|
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-2523
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273618
|
5.0 |
MEDIUM
|
apple
|
safari mac_os_x mac_os_x_server
|
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
|
NVD-CWE-Other
|
CVE-2005-2524
|
2008-09-6 05:51 |
2005-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273619
|
5.0 |
MEDIUM
|
easy_software_products apple
|
cups mac_os_x
|
CUPS in Mac OS X 10.3.9 and 10.4.2 does not properly close file descriptors when handling multiple simultaneous print jobs, which allows remote attackers to cause a denial of service (printing halt).
|
NVD-CWE-Other
|
CVE-2005-2525
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273620
|
5.0 |
MEDIUM
|
easy_software_products apple
|
cups mac_os_x
|
CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consumption) by sending a partial IPP request and closing the connection.
|
NVD-CWE-Other
|
CVE-2005-2526
|
2008-09-6 05:51 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273621
|
7.5 |
HIGH
|
maxwebportal
|
maxwebportal
|
SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.
|
NVD-CWE-Other
|
CVE-2005-1779
|
2008-09-6 05:50 |
2005-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273622
|
5.0 |
MEDIUM
|
mailenable
|
mailenable_enterprise mailenable_professional
|
Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).
|
NVD-CWE-Other
|
CVE-2005-1781
|
2008-09-6 05:50 |
2005-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273623
|
7.5 |
HIGH
|
hosting_controller
|
hosting_controller
|
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.
|
NVD-CWE-Other
|
CVE-2005-1784
|
2008-09-6 05:50 |
2005-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273624
|
7.5 |
HIGH
|
hosting_controller
|
hosting_controller
|
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.
|
NVD-CWE-Other
|
CVE-2005-1788
|
2008-09-6 05:50 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273625
|
4.3 |
MEDIUM
|
w.m.r._simpson
|
bookreview
|
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_revi…
|
NVD-CWE-Other
|
CVE-2005-1782
|
2008-09-6 05:50 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273626
|
7.5 |
HIGH
|
india_software_solution
|
shopping_cart
|
SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.
|
NVD-CWE-Other
|
CVE-2005-1789
|
2008-09-6 05:50 |
2005-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273627
|
5.0 |
MEDIUM
|
microsoft
|
windows_xp
|
Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can b…
|
NVD-CWE-Other
|
CVE-2005-1792
|
2008-09-6 05:50 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273628
|
5.1 |
MEDIUM
|
openssl
|
openssl
|
The design of Advanced Encryption Standard (AES), aka Rijndael, allows remote attackers to recover AES keys via timing attacks on S-box lookups, which are difficult to perform in constant time in AES…
|
NVD-CWE-Other
|
CVE-2005-1797
|
2008-09-6 05:50 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273629
|
5.0 |
MEDIUM
|
serverscheck
|
monitoring_software
|
Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.
|
NVD-CWE-Other
|
CVE-2005-1798
|
2008-09-6 05:50 |
2005-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273630
|
4.3 |
MEDIUM
|
freestyle
|
wiki wikilite
|
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1799
|
2008-09-6 05:50 |
2005-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273631
|
5.0 |
MEDIUM
|
nortel
|
contivity vpn_router_1010 vpn_router_1050 vpn_router_1100 vpn_router_1700 vpn_router_1740 vpn_router_2700 vpn_router_5000 vpn_router_600
|
Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header.
|
NVD-CWE-Other
|
CVE-2005-1802
|
2008-09-6 05:50 |
2005-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273632
|
4.3 |
MEDIUM
|
net_portal_dynamic_system
|
net_portal_dynamic_system
|
Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) admin.php, …
|
NVD-CWE-Other
|
CVE-2005-1803
|
2008-09-6 05:50 |
2005-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273633
|
7.5 |
HIGH
|
net_portal_dynamic_system
|
net_portal_dynamic_system
|
Multiple SQL injection vulnerabilities in Net Portal Dynamic System (NPDS) 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) terme parameter in the glossaire module (glossaire.…
|
NVD-CWE-Other
|
CVE-2005-1804
|
2008-09-6 05:50 |
2005-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273634
|
4.3 |
MEDIUM
|
mybulletinboard
|
mybulletinboard
|
Cross-site scripting (XSS) vulnerability in usercp.php for MyBulletinBoard (MyBB) allows remote attackers to inject arbitrary web script or HTML via the website field in a user profile.
|
NVD-CWE-Other
|
CVE-2005-1811
|
2008-09-6 05:50 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273635
|
5.0 |
MEDIUM
|
hummingbird
|
connectivity
|
Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long a…
|
NVD-CWE-Other
|
CVE-2005-1815
|
2008-09-6 05:50 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273636
|
4.6 |
MEDIUM
|
invision_power_services
|
invision_board
|
Invision Power Board (IPB) 1.0 through 2.0.4 allows non-root admins to add themselves or other users to the root admin group via the "Move users in this group to" screen.
|
NVD-CWE-Other
|
CVE-2005-1816
|
2008-09-6 05:50 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273637
|
5.0 |
MEDIUM
|
invision_power_services
|
invision_board
|
Invision Power Board (IPB) 1.0 through 1.3 allows remote attackers to edit arbitrary forum posts via a direct request to index.php with modified parameters.
|
NVD-CWE-Other
|
CVE-2005-1817
|
2008-09-6 05:50 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273638
|
7.5 |
HIGH
|
newlife_blogger
|
newlife_blogger
|
Multiple SQL injection vulnerabilities in NewLife Blogger before 3.3.1 allow remote attackers to execute arbitrary SQL commands via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-1818
|
2008-09-6 05:50 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273639
|
4.3 |
MEDIUM
|
nikosoft
|
webmail
|
Cross-site scripting (XSS) vulnerability in NikoSoft WebMail before 0.11.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1819
|
2008-09-6 05:50 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273640
|
7.5 |
HIGH
|
zeroboard
|
zeroboard
|
zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function.
|
NVD-CWE-Other
|
CVE-2005-1820
|
2008-09-6 05:50 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273641
|
7.5 |
HIGH
|
gnu
|
mailutils
|
The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which is used as an escape character and makes the modu…
|
NVD-CWE-Other
|
CVE-2005-1824
|
2008-09-6 05:50 |
2005-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273642
|
2.1 |
LOW
|
adobe
|
acrobat_reader
|
The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF …
|
NVD-CWE-Other
|
CVE-2005-1841
|
2008-09-6 05:50 |
2005-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273643
|
2.1 |
LOW
|
adobe
|
version_cue
|
VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, creates temporary log files with predictable names, which…
|
NVD-CWE-Other
|
CVE-2005-1842
|
2008-09-6 05:50 |
2005-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273644
|
4.6 |
MEDIUM
|
adobe
|
version_cue
|
VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with Version Cue Workspace, allows local users to load arbitrary libraries and execut…
|
NVD-CWE-Other
|
CVE-2005-1843
|
2008-09-6 05:50 |
2005-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273645
|
5.0 |
MEDIUM
|
yamt
|
yamt
|
Multiple directory traversal vulnerabilities in YaMT before 0.5_2 allow attackers to overwrite arbitrary files via the (1) rename or (2) sort options.
|
NVD-CWE-Other
|
CVE-2005-1846
|
2008-09-6 05:50 |
2005-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273646
|
7.5 |
HIGH
|
yamt
|
yamt
|
Multiple buffer overflows in YaMT before 0.5_2 allow attackers to execute arbitrary code via the (1) rename or (2) sort options.
|
NVD-CWE-Other
|
CVE-2005-1847
|
2008-09-6 05:50 |
2005-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273647
|
5.0 |
MEDIUM
|
phystech
|
dhcpcd
|
The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.
|
NVD-CWE-Other
|
CVE-2005-1848
|
2008-09-6 05:50 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273648
|
7.2 |
HIGH
|
university_of_minnesota
|
gopher
|
gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-1853
|
2008-09-6 05:50 |
2005-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273649
|
2.1 |
LOW
|
sukria debian
|
backup_manager debian_linux
|
Backup Manager (backup-manager) before 0.5.8 creates backup files with world-readable default permissions, which allows local users to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-1855
|
2008-09-6 05:50 |
2005-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
273650
|
2.1 |
LOW
|
-
|
-
|
The CD-burning feature in backup-manager 0.5.8 and earlier uses a fixed filename in a world-writable directory for logging, which allows local users to overwrite files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2005-1856
|
2008-09-6 05:50 |
2005-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|