|
346001
|
7.5 |
HIGH
|
etype
|
eserv
|
Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.
|
NVD-CWE-Other
|
CVE-2002-0222
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346002
|
7.5 |
HIGH
|
infopop wired_community_software
|
ultimate_bulletin_board wwwthreads
|
Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends i…
|
NVD-CWE-Other
|
CVE-2002-0223
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346003
|
5.0 |
MEDIUM
|
microsoft
|
msn_messenger
|
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more wh…
|
NVD-CWE-Other
|
CVE-2002-0228
|
2008-09-11 09:00 |
2002-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346004
|
7.2 |
HIGH
|
caldera
|
unixware
|
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message cat…
|
NVD-CWE-Other
|
CVE-2002-0246
|
2008-09-11 09:00 |
2002-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346005
|
7.2 |
HIGH
|
wliang
|
wmtv
|
Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0247
|
2008-09-11 09:00 |
2002-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346006
|
7.2 |
HIGH
|
wliang
|
wmtv
|
wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file.
|
NVD-CWE-Other
|
CVE-2002-0248
|
2008-09-11 09:00 |
2002-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346007
|
10.0 |
HIGH
|
caldera
|
unixware openunix
|
Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi…
|
NVD-CWE-Other
|
CVE-2002-0311
|
2008-09-11 09:00 |
2002-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346008
|
7.1 |
HIGH
|
madwifi
|
madwifi
|
The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a con…
|
NVD-CWE-Other
|
CVE-2005-4835
|
2008-09-11 04:54 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346009
|
10.0 |
HIGH
|
spey
|
spey
|
Unspecified vulnerability in Spey 0.3.3 has unknown impact and attack vectors related to "A number of security holes which could lead to compromise," a different issue than CVE-2005-4846.
|
NVD-CWE-noinfo
|
CVE-2005-4847
|
2008-09-11 04:54 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346010
|
4.3 |
MEDIUM
|
ocomon
|
ocomon
|
Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-4663
|
2008-09-11 04:53 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346011
|
7.5 |
HIGH
|
rarlab
|
winrar
|
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when Wi…
|
NVD-CWE-Other
|
CVE-2005-3262
|
2008-09-11 04:46 |
2005-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346012
|
7.5 |
HIGH
|
rarlab
|
winrar
|
Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name.
|
NVD-CWE-Other
|
CVE-2005-3263
|
2008-09-11 04:46 |
2005-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346013
|
7.5 |
HIGH
|
accelerated_enterprise_solutions
|
accelerated_mortgage_manager
|
SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field.
|
NVD-CWE-Other
|
CVE-2005-3290
|
2008-09-11 04:46 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346014
|
5.0 |
MEDIUM
|
squid suse
|
squid suse_linux
|
Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).
|
NVD-CWE-Other
|
CVE-2005-3322
|
2008-09-11 04:46 |
2005-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346015
|
7.2 |
HIGH
|
sco
|
unixware
|
Stack-based buffer overflow in ppp in SCO Unixware 7.1.3 and 7.1.4, and possibly earlier versions, allows local users to execute arbitrary code via a long argument to the (1) prompt or (2) defprompt …
|
NVD-CWE-Other
|
CVE-2005-2927
|
2008-09-11 04:44 |
2005-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346016
|
6.8 |
MEDIUM
|
ibm
|
rational_clearquest
|
Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (X…
|
NVD-CWE-Other
|
CVE-2005-2994
|
2008-09-11 04:44 |
2005-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346017
|
5.1 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execute arbitrary code via a crafted Microsoft Word file.
|
NVD-CWE-Other
|
CVE-2005-2502
|
2008-09-11 04:42 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346018
|
4.6 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.
|
NVD-CWE-Other
|
CVE-2005-2503
|
2008-09-11 04:42 |
2005-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346019
|
10.0 |
HIGH
|
jed_wing
|
chm_lib
|
Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2005-2659
|
2008-09-11 04:42 |
2005-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346020
|
2.1 |
LOW
|
netbsd
|
netbsd
|
The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block …
|
NVD-CWE-Other
|
CVE-2005-2134
|
2008-09-11 04:41 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346021
|
7.5 |
HIGH
|
easyphpcalendar
|
easyphpcalendar
|
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
|
NVD-CWE-Other
|
CVE-2005-2155
|
2008-09-11 04:41 |
2005-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346022
|
7.5 |
HIGH
|
mms_ripper
|
mms_ripper
|
Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams.
|
NVD-CWE-Other
|
CVE-2005-2213
|
2008-09-11 04:41 |
2005-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346023
|
4.3 |
MEDIUM
|
seo-board
|
seo-board
|
Cross-site scripting (XSS) vulnerability in smilies_popup.php in SEO-Board 1.0 allows remote attackers to inject arbitrary web script or HTML via the doc parameter.
|
NVD-CWE-Other
|
CVE-2005-2333
|
2008-09-11 04:41 |
2005-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346024
|
7.5 |
HIGH
|
electricmonk
|
proms
|
Multiple unknown vulnerabilities in PROMS 0.11 allow "non-authorized users" to (1) view or modify the project member list or (2) modify the todos list.
|
NVD-CWE-Other
|
CVE-2005-1737
|
2008-09-11 04:40 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346025
|
5.0 |
MEDIUM
|
w.m.r._simpson
|
bookreview
|
BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect …
|
NVD-CWE-Other
|
CVE-2005-1783
|
2008-09-11 04:40 |
2005-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346026
|
2.6 |
LOW
|
microsoft
|
windows_98se
|
User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and …
|
NVD-CWE-Other
|
CVE-2005-1793
|
2008-09-11 04:40 |
2005-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346027
|
4.3 |
MEDIUM
|
clam_anti-virus
|
clamav
|
Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to ind…
|
NVD-CWE-Other
|
CVE-2005-1800
|
2008-09-11 04:40 |
2005-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346028
|
2.6 |
LOW
|
nokia
|
9500
|
The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.
|
NVD-CWE-Other
|
CVE-2005-1801
|
2008-09-11 04:40 |
2005-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346029
|
7.5 |
HIGH
|
crob
|
crob_ftp
|
Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command wit…
|
NVD-CWE-Other
|
CVE-2005-1873
|
2008-09-11 04:40 |
2005-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346030
|
3.6 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.
|
NVD-CWE-Other
|
CVE-2005-1430
|
2008-09-11 04:39 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346031
|
5.1 |
MEDIUM
|
ht_editor
|
ht_editor
|
Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow.
|
NVD-CWE-Other
|
CVE-2005-1545
|
2008-09-11 04:39 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346032
|
5.1 |
MEDIUM
|
ht_editor
|
ht_editor
|
Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.
|
NVD-CWE-Other
|
CVE-2005-1546
|
2008-09-11 04:39 |
2005-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346033
|
7.5 |
HIGH
|
opentools
|
attachment_mod
|
Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2005-1630
|
2008-09-11 04:39 |
2005-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346034
|
4.3 |
MEDIUM
|
horde
|
accounts
|
Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1316
|
2008-09-11 04:38 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346035
|
7.5 |
HIGH
|
apache
|
http_server
|
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgi…
|
NVD-CWE-Other
|
CVE-2005-1344
|
2008-09-11 04:38 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346036
|
5.1 |
MEDIUM
|
sylpheed
|
sylpheed
|
Buffer overflow in Sylpheed before 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attachments with MIME-encoded file names.
|
NVD-CWE-Other
|
CVE-2005-0926
|
2008-09-11 04:37 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346037
|
4.6 |
MEDIUM
|
uim mandrakesoft
|
uim mandrake_linux
|
uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0503
|
2008-09-11 04:36 |
2005-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346038
|
4.6 |
MEDIUM
|
-
|
-
|
Unknown vulnerability in Squiggle for Batik before 1.5.1 allows attackers to bypass certain access controls via certain features of the Rhino scripting engine due to a "script security issue."
|
NVD-CWE-Other
|
CVE-2005-0508
|
2008-09-11 04:36 |
2005-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346039
|
7.5 |
HIGH
|
mcafee
|
antivirus_engine
|
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA files.
|
NVD-CWE-Other
|
CVE-2005-0643
|
2008-09-11 04:36 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346040
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.
|
NVD-CWE-Other
|
CVE-2005-0712
|
2008-09-11 04:36 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346041
|
5.0 |
MEDIUM
|
clam_anti-virus
|
clamav
|
ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.
|
NVD-CWE-Other
|
CVE-2005-0133
|
2008-09-11 04:35 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346042
|
7.5 |
HIGH
|
smartlist
|
smartlist
|
The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie…
|
NVD-CWE-Other
|
CVE-2005-0157
|
2008-09-11 04:35 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346043
|
5.0 |
MEDIUM
|
clam_anti-virus
|
clamav
|
ClamAV 0.80 and earlier allows remote attackers to bypass virus scanning via a base64 encoded image in a data: (RFC 2397) URL.
|
NVD-CWE-Other
|
CVE-2005-0218
|
2008-09-11 04:35 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346044
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb
|
Directory traversal vulnerability in (1) usercp_register.php and (2) usercp_avatar.php for phpBB 2.0.11, and possibly other versions, with gallery avatars enabled, allows remote attackers to delete (…
|
NVD-CWE-Other
|
CVE-2005-0258
|
2008-09-11 04:35 |
2005-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346045
|
6.4 |
MEDIUM
|
phpbb_group
|
phpbb
|
phpBB 2.0.11, and possibly other versions, with remote avatars and avatar uploading enabled, allows local users to read arbitrary files by providing both a local and remote location for an avatar, th…
|
NVD-CWE-Other
|
CVE-2005-0259
|
2008-09-11 04:35 |
2005-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346046
|
4.3 |
MEDIUM
|
zakon_group
|
openconf
|
Cross-site scripting (XSS) vulnerability in Openconf 1.04, and possibly other versions before 1.10, allows remote attackers to inject arbitrary HTML and web script via the paper title.
|
NVD-CWE-Other
|
CVE-2005-0407
|
2008-09-11 04:35 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346047
|
6.4 |
MEDIUM
|
citrusdb
|
citrusdb
|
CitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to upload credit card data and obtain sensitive information such …
|
NVD-CWE-Other
|
CVE-2005-0409
|
2008-09-11 04:35 |
2005-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346048
|
5.0 |
MEDIUM
|
citrusdb
|
citrusdb
|
SQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV file.
|
NVD-CWE-Other
|
CVE-2005-0410
|
2008-09-11 04:35 |
2005-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346049
|
7.5 |
HIGH
|
citrusdb
|
citrusdb
|
Directory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary PHP files via .. (dot dot) sequences in the load parameter.
|
NVD-CWE-Other
|
CVE-2005-0411
|
2008-09-11 04:35 |
2005-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346050
|
10.0 |
HIGH
|
gentoo
|
poppassd_pam
|
poppassd_pam 1.0 and earlier, when changing a user password, does not verify that the user entered the old password correctly, which allows remote attackers to change passwords for arbitrary users.
|
NVD-CWE-Other
|
CVE-2005-0002
|
2008-09-11 04:34 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|