275401
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via craf…
|
NVD-CWE-Other
|
CVE-2005-0969
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275402
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
|
NVD-CWE-Other
|
CVE-2005-0971
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275403
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
|
NVD-CWE-Other
|
CVE-2005-0972
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275404
|
2.1 |
LOW
|
apple
|
mac_os_x
|
Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.
|
NVD-CWE-Other
|
CVE-2005-0973
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275405
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
|
NVD-CWE-Other
|
CVE-2005-0974
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275406
|
5.0 |
MEDIUM
|
apple hmdt omnigroup
|
safari shiira omniweb
|
AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript componen…
|
NVD-CWE-Other
|
CVE-2005-0976
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275407
|
2.1 |
LOW
|
-
|
-
|
Unspecified vulnerability in the Mac OS X kernel before 10.3.8 allows local users to cause a denial of service (temporary hang) via unspecified attack vectors related to the fan control unit (FCU) dr…
|
NVD-CWE-Other
|
CVE-2005-0985
|
2008-09-6 05:47 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275408
|
5.0 |
MEDIUM
|
irc_services
|
nickserv_listlinks
|
Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick.
|
NVD-CWE-Other
|
CVE-2005-0987
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275409
|
2.1 |
LOW
|
-
|
-
|
RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.
|
NVD-CWE-Other
|
CVE-2005-0991
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275410
|
4.3 |
MEDIUM
|
early_impact
|
productcart
|
Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirect…
|
NVD-CWE-Other
|
CVE-2005-0995
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275411
|
4.3 |
MEDIUM
|
asp-dev
|
xm_forum
|
Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via a "javascript:" URL in an IMG tag.
|
NVD-CWE-Other
|
CVE-2005-1008
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275412
|
7.5 |
HIGH
|
iatek
|
siteenable
|
SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
|
NVD-CWE-Other
|
CVE-2005-1011
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275413
|
10.0 |
HIGH
|
mailenable
|
imapd
|
Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
|
NVD-CWE-Other
|
CVE-2005-1015
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275414
|
7.5 |
HIGH
|
f-secure
|
f-secure_anti-virus f-secure_internet_security f-secure_personal_express internet_gatekeeper
|
Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.
|
NVD-CWE-Other
|
CVE-2005-0350
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275415
|
4.6 |
MEDIUM
|
sco
|
openserver
|
Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2005-0351
|
2008-09-6 05:46 |
2005-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275416
|
5.0 |
MEDIUM
|
microsoft
|
log_sink_class_activex_control
|
The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0360
|
2008-09-6 05:46 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275417
|
4.6 |
MEDIUM
|
awstats
|
awstats
|
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.
|
NVD-CWE-Other
|
CVE-2005-0362
|
2008-09-6 05:46 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275418
|
7.5 |
HIGH
|
awstats
|
awstats
|
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
|
NVD-CWE-Other
|
CVE-2005-0363
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275419
|
4.3 |
MEDIUM
|
mailreader.com
|
mailreader.com
|
Cross-site scripting (XSS) vulnerability in network.cgi in mailreader before 2.3.29 earlier allows remote attackers to inject arbitrary web script or HTML via MIME text/enriched or text/richtext mess…
|
NVD-CWE-Other
|
CVE-2005-0386
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275420
|
2.1 |
LOW
|
remstats
|
remstats
|
remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-0387
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275421
|
7.5 |
HIGH
|
remstats
|
remstats
|
Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."
|
NVD-CWE-Other
|
CVE-2005-0388
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275422
|
7.2 |
HIGH
|
crip
|
crip
|
The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-0393
|
2008-09-6 05:46 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275423
|
5.0 |
MEDIUM
|
kmail kde
|
kmail kde
|
KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
|
NVD-CWE-Other
|
CVE-2005-0404
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275424
|
7.5 |
HIGH
|
sun
|
j2se
|
Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP fil…
|
NVD-CWE-Other
|
CVE-2005-0418
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275425
|
5.0 |
MEDIUM
|
ibm
|
websphere_application_server
|
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL t…
|
NVD-CWE-Other
|
CVE-2005-0425
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275426
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier fo…
|
NVD-CWE-Other
|
CVE-2005-0432
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275427
|
7.5 |
HIGH
|
awstats
|
awstats
|
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
|
NVD-CWE-Other
|
CVE-2005-0437
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275428
|
4.6 |
MEDIUM
|
vmware
|
workstation
|
VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0444
|
2008-09-6 05:46 |
2005-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275429
|
5.0 |
MEDIUM
|
sami
|
sami_http_server
|
Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.
|
NVD-CWE-Other
|
CVE-2005-0450
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275430
|
5.0 |
MEDIUM
|
sami
|
sami_http_server
|
Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.
|
NVD-CWE-Other
|
CVE-2005-0451
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275431
|
5.0 |
MEDIUM
|
lighttpd
|
lighttpd
|
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL …
|
NVD-CWE-Other
|
CVE-2005-0453
|
2008-09-6 05:46 |
2005-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275432
|
5.0 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP er…
|
NVD-CWE-Other
|
CVE-2005-0459
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275433
|
5.0 |
MEDIUM
|
mercuryboard
|
mercuryboard
|
index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.
|
NVD-CWE-Other
|
CVE-2005-0460
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275434
|
5.0 |
MEDIUM
|
-
|
-
|
Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."
|
NVD-CWE-Other
|
CVE-2005-0461
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275435
|
4.3 |
MEDIUM
|
mercuryboard
|
mercuryboard
|
Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.
|
NVD-CWE-Other
|
CVE-2005-0462
|
2008-09-6 05:46 |
2005-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275436
|
7.5 |
HIGH
|
inl
|
ulog-php
|
Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port…
|
NVD-CWE-Other
|
CVE-2005-0463
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275437
|
2.1 |
LOW
|
sgi
|
irix
|
gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary file…
|
NVD-CWE-Other
|
CVE-2005-0464
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275438
|
2.1 |
LOW
|
sgi
|
irix
|
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.
|
NVD-CWE-Other
|
CVE-2005-0465
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275439
|
7.5 |
HIGH
|
gproftpd
|
gproftpd
|
Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifier…
|
NVD-CWE-Other
|
CVE-2005-0484
|
2008-09-6 05:46 |
2005-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275440
|
4.9 |
MEDIUM
|
linux
|
linux_kernel
|
The /proc handling (proc/base.c) Linux kernel 2.4 before 2.4.17 allows local users to cause a denial of service via unknown vectors that cause an invalid access of free memory.
|
NVD-CWE-Other
|
CVE-2005-0489
|
2008-09-6 05:46 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275441
|
4.9 |
MEDIUM
|
linux
|
linux_kernel
|
This vulnerability is addressed in the following product release:
Linux, Linux kernel, 2.4.27
|
NVD-CWE-Other
|
CVE-2005-0489
|
2008-09-6 05:46 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275442
|
2.1 |
LOW
|
fallback-reboot
|
fallback-reboot
|
The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.
|
NVD-CWE-Other
|
CVE-2005-0510
|
2008-09-6 05:46 |
2005-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275443
|
7.5 |
HIGH
|
mambo
|
mambo
|
PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remo…
|
NVD-CWE-Other
|
CVE-2005-0512
|
2008-09-6 05:46 |
2005-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275444
|
4.3 |
MEDIUM
|
verity
|
verity_ultraseek
|
Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.
|
NVD-CWE-Other
|
CVE-2005-0514
|
2008-09-6 05:46 |
2005-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275445
|
2.1 |
LOW
|
webroot_software
|
my_firewall_plus
|
Smc.exe in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before launching the Log Viewer export functionality, which allows local users to corrupt arbitrary f…
|
NVD-CWE-Other
|
CVE-2005-0515
|
2008-09-6 05:46 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275446
|
2.1 |
LOW
|
peerftp_5
|
peerftp_5
|
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0517
|
2008-09-6 05:46 |
2005-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275447
|
2.1 |
LOW
|
exeem
|
exeem
|
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.
|
NVD-CWE-Other
|
CVE-2005-0518
|
2008-09-6 05:46 |
2005-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275448
|
2.1 |
LOW
|
-
|
-
|
SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0521
|
2008-09-6 05:46 |
2005-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275449
|
4.6 |
MEDIUM
|
lionmax_software
|
chat_anywhere
|
Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0522
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
275450
|
7.5 |
HIGH
|
prozilla
|
prozilla_download_accelerator
|
Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.
|
NVD-CWE-Other
|
CVE-2005-0523
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|