|
345451
|
7.5 |
HIGH
|
ibm
|
aix
|
Buffer overflow in swcons in IBM AIX 5.2, when debug malloc is enabled, allows remote attackers to cause a core dump and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-3504
|
2011-03-8 11:26 |
2005-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345452
|
5.0 |
MEDIUM
|
cutephp
|
cutenews
|
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parameter to (1) show_arc…
|
NVD-CWE-Other
|
CVE-2005-3507
|
2011-03-8 11:26 |
2005-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345453
|
7.5 |
HIGH
|
jportal
|
jportal_web_portal
|
Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banner.php or the id parameter to (2) print.php, (3) comment.php, and (4) news.php.
|
NVD-CWE-Other
|
CVE-2005-3509
|
2011-03-8 11:26 |
2005-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345454
|
2.1 |
LOW
|
miklos_szeredi
|
fuse
|
fusermount in FUSE before 2.4.1, if installed setuid root, allows local users to corrupt /etc/mtab and possibly modify mount options by performing a mount over a directory whose name contains certain…
|
NVD-CWE-Other
|
CVE-2005-3531
|
2011-03-8 11:26 |
2005-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345455
|
7.2 |
HIGH
|
osh
|
osh
|
Buffer overflow in OSH before 1.7-15 allows local users to execute arbitrary code via a long current working directory and filename.
|
NVD-CWE-Other
|
CVE-2005-3533
|
2011-03-8 11:26 |
2005-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345456
|
7.5 |
HIGH
|
peel
|
peel
|
SQL injection vulnerability in index.php in Peel 2.6 through 2.7 allows remote attackers to execute arbitrary SQL commands via the rubid parameter.
|
NVD-CWE-Other
|
CVE-2005-3572
|
2011-03-8 11:26 |
2005-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345457
|
5.0 |
MEDIUM
|
icms_content_management_systems
|
icms
|
PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter.
|
NVD-CWE-Other
|
CVE-2005-3574
|
2011-03-8 11:26 |
2005-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345458
|
7.5 |
HIGH
|
cynox
|
cyphor
|
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
NVD-CWE-Other
|
CVE-2005-3575
|
2011-03-8 11:26 |
2005-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345459
|
7.2 |
HIGH
|
qdbm
|
qdbm
|
QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects i…
|
NVD-CWE-Other
|
CVE-2005-3580
|
2011-03-8 11:26 |
2005-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345460
|
7.2 |
HIGH
|
gdal
|
gdal
|
GDAL before 1.3.0-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in…
|
NVD-CWE-Other
|
CVE-2005-3581
|
2011-03-8 11:26 |
2005-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345461
|
7.2 |
HIGH
|
imagemagick
|
imagemagick
|
ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing o…
|
NVD-CWE-Other
|
CVE-2005-3582
|
2011-03-8 11:26 |
2005-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345462
|
7.5 |
HIGH
|
ubertec
|
help_center_live
|
PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directo…
|
NVD-CWE-Other
|
CVE-2005-3639
|
2011-03-8 11:26 |
2005-11-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345463
|
7.5 |
HIGH
|
citrix
|
ica_program_neighborhood_client
|
Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.
|
NVD-CWE-Other
|
CVE-2005-3652
|
2011-03-8 11:26 |
2005-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345464
|
7.5 |
HIGH
|
bluecoat
|
webproxy
|
Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of packets with 0xFF characters to the …
|
NVD-CWE-Other
|
CVE-2005-3654
|
2011-03-8 11:26 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345465
|
5.0 |
MEDIUM
|
mcafee
|
mcinsctl.dll virusscan_security_center
|
The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or …
|
NVD-CWE-Other
|
CVE-2005-3657
|
2011-03-8 11:26 |
2005-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345466
|
7.2 |
HIGH
|
kaspersky_lab
|
kaspersky_anti-virus
|
Unquoted Windows search path vulnerability in Kaspersky Anti-Virus 5.0 might allow local users to gain privileges via a malicious "program.exe" file in the C: folder.
|
NVD-CWE-Other
|
CVE-2005-3663
|
2011-03-8 11:26 |
2005-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345467
|
5.0 |
MEDIUM
|
stonesoft
|
stonegate_firewall
|
The Internet Key Exchange version 1 (IKEv1) implementation in Stonesoft StoneGate Firewall before 2.6.1 allows remote attackers to cause a denial of service via certain crafted IKE packets, as demons…
|
NVD-CWE-Other
|
CVE-2005-3672
|
2011-03-8 11:26 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345468
|
7.8 |
HIGH
|
checkpoint
|
check_point express firewall-1 vpn-1 vpn-1_firewall-1_next_generation
|
The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS …
|
NVD-CWE-Other
|
CVE-2005-3673
|
2011-03-8 11:26 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345469
|
7.8 |
HIGH
|
sun
|
solaris
|
The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Sun Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked crash) via certain crafted IKE p…
|
NVD-CWE-Other
|
CVE-2005-3674
|
2011-03-8 11:26 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345470
|
4.3 |
MEDIUM
|
virtual_programming
|
vp-asp
|
Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject arbitrary web script or HTML via the UserName parameter.
|
NVD-CWE-Other
|
CVE-2005-3685
|
2011-03-8 11:26 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345471
|
5.0 |
MEDIUM
|
-
|
-
|
Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mai…
|
NVD-CWE-Other
|
CVE-2005-3691
|
2011-03-8 11:26 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345472
|
4.3 |
MEDIUM
|
amax_information_technologies
|
magic_winmail_server
|
Cross-site scripting (XSS) vulnerability in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) retid parameter in badlog…
|
NVD-CWE-Other
|
CVE-2005-3692
|
2011-03-8 11:26 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345473
|
9.3 |
HIGH
|
sunncomm_mediamax
|
axwebremovectrl
|
The AxWebRemoveCtrl ActiveX control for uninstalling the SunnComm MediaMax DRM allows remote attackers to download and execute arbitrary code, a similar vulnerability to CVE-2005-3650.
|
NVD-CWE-Other
|
CVE-2005-3693
|
2011-03-8 11:26 |
2005-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345474
|
4.3 |
MEDIUM
|
litespeed_technologies
|
litespeed_web_server
|
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attackers to inject arbitrary web script or HTML via the m parameter.
|
NVD-CWE-Other
|
CVE-2005-3695
|
2011-03-8 11:26 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345475
|
7.5 |
HIGH
|
openttd
|
openttd
|
Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2005-2763
|
2011-03-8 11:25 |
2005-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345476
|
7.5 |
HIGH
|
openttd
|
openttd
|
Multiple buffer overflows in OpenTTD before 0.4.0.1 allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2005-2764
|
2011-03-8 11:25 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345477
|
4.3 |
MEDIUM
|
eric_fichot
|
downfile
|
Cross-site scripting (XSS) vulnerability in DownFile 1.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter to (1) email.php,(2) index.php, (3) del.php, or (4) add_fo…
|
CWE-79
Cross-site Scripting
|
CVE-2005-2818
|
2011-03-8 11:25 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345478
|
4.0 |
MEDIUM
|
ipswitch
|
imail_server ipswitch_collaboration_suite
|
The IMAP server in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to cause a denial of service (crash) via a long argument to the LIST command, which caus…
|
CWE-20
Improper Input Validation
|
CVE-2005-2923
|
2011-03-8 11:25 |
2005-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345479
|
7.5 |
HIGH
|
ipswitch
|
imail_server ipswitch_collaboration_suite
|
Format string vulnerability in the SMTP service in IMail Server 8.20 in Ipswitch Collaboration Suite (ICS) before 2.02 allows remote attackers to execute arbitrary code via format string specifiers t…
|
NVD-CWE-Other
|
CVE-2005-2931
|
2011-03-8 11:25 |
2005-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345480
|
7.5 |
HIGH
|
deluxebb
|
deluxebb
|
Multiple SQL injection vulnerabilities in DeluxeBB 1.0 and 1.0.5 allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter to topic.php, the uid parameter to (2) misc.php or …
|
NVD-CWE-Other
|
CVE-2005-2989
|
2011-03-8 11:25 |
2005-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345481
|
2.1 |
LOW
|
linecontrol
|
java_client
|
AuthInfo.java in LineContol Java Client (jlc) before 0.8.1 stores sensitive information such as user passwords in log files.
|
NVD-CWE-Other
|
CVE-2005-2990
|
2011-03-8 11:25 |
2005-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345482
|
2.1 |
LOW
|
sun
|
solaris
|
Unspecified vulnerability in the "tl" driver in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3001
|
2011-03-8 11:25 |
2005-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345483
|
5.0 |
MEDIUM
|
xclusive-software
|
mccs
|
Multi-Computer Control System (MCCS) 1.0 allows remote attackers to cause a denial of service via a malformed UDP packet.
|
NVD-CWE-Other
|
CVE-2005-3002
|
2011-03-8 11:25 |
2005-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345484
|
7.5 |
HIGH
|
usermin webmin
|
usermin webmin
|
miniserv.pl in Webmin before 1.230 and Usermin before 1.160, when "full PAM conversations" is enabled, allows remote attackers to bypass authentication by spoofing session IDs via certain metacharact…
|
NVD-CWE-Other
|
CVE-2005-3042
|
2011-03-8 11:25 |
2005-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345485
|
4.3 |
MEDIUM
|
scriptsolutions
|
perldiver
|
Cross-site scripting (XSS) vulnerability in perldiver.pl in PerlDiver 1.x allows remote attackers to inject arbitrary web script or HTML via the query string. NOTE: this issue was originally dispute…
|
NVD-CWE-Other
|
CVE-2005-3066
|
2011-03-8 11:25 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345486
|
4.3 |
MEDIUM
|
scriptsolutions
|
perldiver
|
Cross-site scripting (XSS) vulnerability in perldiver.cgi in PerlDiver 2.x allows remote attackers to inject arbitrary web script or HTML via the module parameter.
|
NVD-CWE-Other
|
CVE-2005-3067
|
2011-03-8 11:25 |
2005-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345487
|
4.6 |
MEDIUM
|
qualcomm
|
qpopper
|
poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace file) command line argument.
|
NVD-CWE-Other
|
CVE-2005-3098
|
2011-03-8 11:25 |
2005-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345488
|
7.5 |
HIGH
|
william_stearns
|
mason
|
Mason before 1.0.0 does not install the init script after the user uses Mason to configure a firewall, which causes the system to run without a firewall after a reboot.
|
NVD-CWE-Other
|
CVE-2005-3118
|
2011-03-8 11:25 |
2005-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345489
|
5.0 |
MEDIUM
|
gnu
|
gnump3d
|
Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".."…
|
NVD-CWE-Other
|
CVE-2005-3123
|
2011-03-8 11:25 |
2005-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345490
|
2.1 |
LOW
|
acme_labs
|
thttpd
|
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
|
NVD-CWE-Other
|
CVE-2005-3124
|
2011-03-8 11:25 |
2005-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345491
|
4.6 |
MEDIUM
|
uim
|
uim
|
Uim 0.4.x before 0.4.9.1 and 0.5.0 and earlier does not properly handle the LIBUIM_VANILLA environment variable when a suid or sgid application is linked to libuim, such as immodule for Qt, which all…
|
NVD-CWE-Other
|
CVE-2005-3149
|
2011-03-8 11:25 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345492
|
5.0 |
MEDIUM
|
bluecoat
|
winproxy
|
The listening daemon in Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) via a long HTTP request that causes an out-of-bounds read.
|
NVD-CWE-Other
|
CVE-2005-3187
|
2011-03-8 11:25 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345493
|
5.0 |
MEDIUM
|
qualcomm
|
worldmail_imap_server
|
Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email messages via ".." sequences in the SELECT command.
|
NVD-CWE-Other
|
CVE-2005-3189
|
2011-03-8 11:25 |
2005-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345494
|
9.3 |
HIGH
|
nullsoft
|
winamp
|
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TIT…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2005-2310
|
2011-03-8 11:24 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345495
|
7.5 |
HIGH
|
phpsftpd
|
phpsftpd
|
inc.login.php in PHPsFTPd 0.2 through 0.4 allows remote attackers to obtain the administrator's username and password by setting the do_login parameter and performing an edit action using user.php, w…
|
NVD-CWE-Other
|
CVE-2005-2314
|
2011-03-8 11:24 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345496
|
7.8 |
HIGH
|
rim
|
blackberry_enterprise_server blackberry_router
|
Research in Motion (RIM) BlackBerry Router allows remote attackers to cause a denial of service (communication disruption) via crafted Server Routing Protocol (SRP) packets.
|
NVD-CWE-Other
|
CVE-2005-2342
|
2011-03-8 11:24 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345497
|
2.6 |
LOW
|
rim
|
blackberry_desktop_manager blackberry_device_software blackberry
|
Research in Motion (RIM) BlackBerry Handheld web browser for BlackBerry Handheld before 4.0.2 allows remote attackers to cause a denial of service (hang) via a Java Application Description (JAD) file…
|
NVD-CWE-Other
|
CVE-2005-2343
|
2011-03-8 11:24 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345498
|
4.3 |
MEDIUM
|
my_image_gallery
|
my_image_gallery
|
Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) currDir or (2) image parameters.
|
NVD-CWE-Other
|
CVE-2005-2603
|
2011-03-8 11:24 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345499
|
5.0 |
MEDIUM
|
my_image_gallery
|
my_image_gallery
|
index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to obtain the web server path via certain currDir and image arguments, which leaks the path in an error message.
|
NVD-CWE-Other
|
CVE-2005-2604
|
2011-03-8 11:24 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345500
|
7.5 |
HIGH
|
phlymail
|
phlymail
|
Unknown vulnerability in the "frontend authentication" in PHlyMail 3.02.00 has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2005-2606
|
2011-03-8 11:24 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|