|
345501
|
7.5 |
HIGH
|
ezupload
|
ezupload
|
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.…
|
NVD-CWE-Other
|
CVE-2005-2616
|
2011-03-8 11:24 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345502
|
10.0 |
HIGH
|
kismet
|
kismet
|
Unspecified vulnerability in Kismet before 2005-08-R1 allows remote attackers to have an unknown impact via unprintable characters in the SSID.
|
NVD-CWE-Other
|
CVE-2005-2626
|
2011-03-8 11:24 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345503
|
7.5 |
HIGH
|
kismet
|
kismet
|
Multiple integer underflows in Kismet before 2005-08-R1 allow remote attackers to execute arbitrary code via (1) kernel headers in a pcap file or (2) data frame dissection, which leads to heap-based …
|
NVD-CWE-Other
|
CVE-2005-2627
|
2011-03-8 11:24 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345504
|
7.5 |
HIGH
|
up-imapproxy
|
up-imapproxy
|
Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows remote IMAP servers to execute arbitrary code via format string specifiers in a …
|
NVD-CWE-Other
|
CVE-2005-2661
|
2011-03-8 11:24 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345505
|
2.1 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before reusing it, which could allow attackers to obtain sensitive information, a different vulnerability…
|
CWE-200
Information Exposure
|
CVE-2005-2752
|
2011-03-8 11:24 |
2005-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345506
|
7.2 |
HIGH
|
symantec
|
norton_antivirus
|
** SPLIT ** The jlucaller program in LiveUpdate for Symantec Norton AntiVirus 9.0.3 on Macintosh runs setuid when executing Java programs, which allows local users to gain privileges. NOTE: due to a…
|
NVD-CWE-Other
|
CVE-2005-2759
|
2011-03-8 11:24 |
2005-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345507
|
5.0 |
MEDIUM
|
-
|
-
|
Directory traversal vulnerability in Dzip before 2.9 allows remote attackers to create arbitrary files via a filename containing a .. (dot dot) in a .dz archive.
|
NVD-CWE-Other
|
CVE-2005-1874
|
2011-03-8 11:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345508
|
5.0 |
MEDIUM
|
sun
|
java_system_web_server
|
Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files.
|
NVD-CWE-Other
|
CVE-2005-1889
|
2011-03-8 11:23 |
2005-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345509
|
5.0 |
MEDIUM
|
flatnuke
|
flatnuke
|
FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.
|
NVD-CWE-Other
|
CVE-2005-1893
|
2011-03-8 11:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345510
|
4.3 |
MEDIUM
|
flatnuke
|
flatnuke
|
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.
|
NVD-CWE-Other
|
CVE-2005-1895
|
2011-03-8 11:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345511
|
5.0 |
MEDIUM
|
flatnuke
|
flatnuke
|
Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation path via the image parameter.
|
NVD-CWE-Other
|
CVE-2005-1896
|
2011-03-8 11:23 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345512
|
2.1 |
LOW
|
log4sh
|
log4sh
|
The log4sh_readProperties function in log4sh 1.2.5 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable log4sh.$$ filenames.
|
NVD-CWE-Other
|
CVE-2005-1915
|
2011-03-8 11:23 |
2005-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345513
|
5.0 |
MEDIUM
|
trend_micro
|
serverprotect
|
Directory traversal vulnerability in the Crystal Report component (rptserver.asp) in Trend Micro ServerProtect Management Console 5.58, as used in Control Manager 2.5 and 3.0 and Damage Cleanup Serve…
|
NVD-CWE-Other
|
CVE-2005-1930
|
2011-03-8 11:23 |
2005-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345514
|
5.0 |
MEDIUM
|
3com
|
3c15100d
|
Directory traversal vulnerability in the web server for 3Com Network Supervisor 5.0.2 allows remote attackers to read arbitrary files via ".." sequences in the URL to TCP port 21700.
|
NVD-CWE-Other
|
CVE-2005-2020
|
2011-03-8 11:23 |
2005-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345515
|
4.3 |
MEDIUM
|
sun
|
iplanet_messaging_server one_messaging_server
|
Unknown vulnerability in Webmail in iPlanet Messaging Server 5.2 Patch 1 and Sun ONE Messaging Server 6.2 allows remote attackers to execute arbitrary Javascript, possibly due to a cross-site scripti…
|
NVD-CWE-noinfo CWE-79
Cross-site Scripting
|
CVE-2005-2022
|
2011-03-8 11:23 |
2005-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345516
|
7.5 |
HIGH
|
-
|
-
|
Multiple SQL injection vulnerabilities in Fortibus CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via (1) the username or password to logon.asp, (2) WeeklyNotesDisplay.asp, or (3)…
|
NVD-CWE-Other
|
CVE-2005-2037
|
2011-03-8 11:23 |
2005-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345517
|
2.1 |
LOW
|
hp
|
version_control_repository_manager
|
HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of th…
|
NVD-CWE-Other
|
CVE-2005-2076
|
2011-03-8 11:23 |
2005-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345518
|
5.0 |
MEDIUM
|
pavsta
|
pavsta_auto_site
|
PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.
|
NVD-CWE-Other
|
CVE-2005-2139
|
2011-03-8 11:23 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345519
|
10.0 |
HIGH
|
the_cacti_group
|
cacti
|
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL i…
|
NVD-CWE-Other
|
CVE-2005-2149
|
2011-03-8 11:23 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345520
|
5.0 |
MEDIUM
|
nabocorp
|
nabopoll
|
PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter.
|
NVD-CWE-Other
|
CVE-2005-2157
|
2011-03-8 11:23 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345521
|
5.0 |
MEDIUM
|
ibm
|
tivoli_management_framework
|
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connec…
|
NVD-CWE-Other
|
CVE-2005-2170
|
2011-03-8 11:23 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345522
|
6.4 |
MEDIUM
|
novell
|
netmail
|
Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
|
NVD-CWE-Other
|
CVE-2005-2176
|
2011-03-8 11:23 |
2005-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345523
|
5.0 |
MEDIUM
|
leafnode
|
leafnode
|
fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article bod…
|
NVD-CWE-Other
|
CVE-2005-1453
|
2011-03-8 11:22 |
2005-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345524
|
7.5 |
HIGH
|
cisco
|
firewall_services_module
|
Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs).
|
NVD-CWE-Other
|
CVE-2005-1517
|
2011-03-8 11:22 |
2005-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345525
|
5.0 |
MEDIUM
|
apple
|
quicktime
|
Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read lo…
|
NVD-CWE-Other
|
CVE-2005-1579
|
2011-03-8 11:22 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345526
|
5.0 |
MEDIUM
|
niteenterprises
|
remote_file_manager
|
NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080.
|
NVD-CWE-Other
|
CVE-2005-1603
|
2011-03-8 11:22 |
2005-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345527
|
7.5 |
HIGH
|
woltlab
|
burning_board
|
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable.
|
NVD-CWE-Other
|
CVE-2005-1642
|
2011-03-8 11:22 |
2005-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345528
|
7.5 |
HIGH
|
fastream
|
netfile_ftp_web_server
|
The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows…
|
NVD-CWE-Other
|
CVE-2005-1646
|
2011-03-8 11:22 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345529
|
4.6 |
MEDIUM
|
gentoo
|
linux_webapp-config
|
The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.
|
NVD-CWE-Other
|
CVE-2005-1707
|
2011-03-8 11:22 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345530
|
7.5 |
HIGH
|
bluecoat
|
reporter
|
Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license.
|
NVD-CWE-Other
|
CVE-2005-1709
|
2011-03-8 11:22 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345531
|
4.3 |
MEDIUM
|
netwin
|
surgemail
|
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1714
|
2011-03-8 11:22 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345532
|
9.3 |
HIGH
|
novell
|
imanager
|
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonst…
|
NVD-CWE-Other
|
CVE-2005-1730
|
2011-03-8 11:22 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345533
|
9.3 |
HIGH
|
novell
|
imanager
|
This vulnerability is addressed in the following product update:
http://www.novell.com/products/consoles/
|
NVD-CWE-Other
|
CVE-2005-1730
|
2011-03-8 11:22 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345534
|
5.0 |
MEDIUM
|
gearbox_software
|
halo_combat_evolved
|
Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data.
|
NVD-CWE-Other
|
CVE-2005-1741
|
2011-03-8 11:22 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345535
|
4.3 |
MEDIUM
|
novell
|
netmail
|
Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields.
|
NVD-CWE-Other
|
CVE-2005-1756
|
2011-03-8 11:22 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345536
|
7.5 |
HIGH
|
novell
|
netmail
|
Buffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-1757
|
2011-03-8 11:22 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345537
|
7.5 |
HIGH
|
novell
|
netmail
|
Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-1758
|
2011-03-8 11:22 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345538
|
5.0 |
MEDIUM
|
phpmailer
|
phpmailer
|
The Data function in class.smtp.php in PHPMailer 1.7.2 and earlier allows remote attackers to cause a denial of service (infinite loop leading to memory and CPU consumption) via a long header field.
|
NVD-CWE-Other
|
CVE-2005-1807
|
2011-03-8 11:22 |
2005-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345539
|
7.5 |
HIGH
|
hp
|
radia_client
|
Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to exe…
|
NVD-CWE-Other
|
CVE-2005-1825
|
2011-03-8 11:22 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345540
|
7.5 |
HIGH
|
hp
|
radia_client
|
Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension.
|
NVD-CWE-Other
|
CVE-2005-1826
|
2011-03-8 11:22 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345541
|
7.5 |
HIGH
|
kerio
|
kerio_mailserver personal_firewall winroute_firewall
|
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 …
|
NVD-CWE-Other
|
CVE-2005-1062
|
2011-03-8 11:21 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345542
|
5.1 |
MEDIUM
|
apple
|
applescript mac_os_x mac_os_x_server
|
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could…
|
NVD-CWE-Other
|
CVE-2005-1331
|
2011-03-8 11:21 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345543
|
5.1 |
MEDIUM
|
apple
|
terminal mac_os_x mac_os_x_server
|
Apple Terminal 1.4.4 allows attackers to execute arbitrary commands via terminal escape sequences.
|
NVD-CWE-Other
|
CVE-2005-1341
|
2011-03-8 11:21 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345544
|
7.5 |
HIGH
|
apple
|
terminal mac_os_x
|
The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2005-1342
|
2011-03-8 11:21 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345545
|
4.6 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.
|
NVD-CWE-Other
|
CVE-2005-1392
|
2011-03-8 11:21 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345546
|
4.6 |
MEDIUM
|
freebsd
|
freebsd
|
The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications t…
|
NVD-CWE-Other
|
CVE-2005-1406
|
2011-03-8 11:21 |
2005-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345547
|
5.0 |
MEDIUM
|
soft3304
|
04webserver
|
Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.
|
NVD-CWE-Other
|
CVE-2005-1416
|
2011-03-8 11:21 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345548
|
7.5 |
HIGH
|
stefan_ritt
|
elog_web_logbook
|
ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.
|
NVD-CWE-Other
|
CVE-2005-0440
|
2011-03-8 11:20 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345549
|
4.3 |
MEDIUM
|
mediawiki
|
mediawiki
|
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allow remote attackers to inject arbitrary web script.
|
NVD-CWE-Other
|
CVE-2005-0534
|
2011-03-8 11:20 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345550
|
7.5 |
HIGH
|
mediawiki gentoo
|
mediawiki linux
|
Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.
|
NVD-CWE-Other
|
CVE-2005-0535
|
2011-03-8 11:20 |
2005-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|