|
347051
|
4.3 |
MEDIUM
|
pixel-apes_group
|
safehtml
|
The _writeAttrs function in SafeHTML before 1.3.2 does not properly handle quotes in attribute values, which could allow remote attackers to exploit cross-site scripting (XSS) vulnerabilities in appl…
|
NVD-CWE-Other
|
CVE-2005-1638
|
2008-09-6 05:49 |
2005-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347052
|
7.5 |
HIGH
|
the_ignition_project
|
ignitionserver
|
mod_channel.bas in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not properly verify whether a host has the owner privileges required to delete IRC channel a…
|
NVD-CWE-Other
|
CVE-2005-1640
|
2008-09-6 05:49 |
2005-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347053
|
2.1 |
LOW
|
the_ignition_project
|
ignitionserver
|
mod_channel in The Ignition Project ignitionServer 0.3.0 to 0.3.6, and possibly earlier versions, does not allow protected operators to access channels that have been locked out by a key, which allow…
|
NVD-CWE-Other
|
CVE-2005-1641
|
2008-09-6 05:49 |
2005-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347054
|
7.5 |
HIGH
|
gurgens
|
gurgens_guest_book
|
Gurgens (GASoft) Guest Book 2.1 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames and p…
|
NVD-CWE-Other
|
CVE-2005-1647
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347055
|
7.5 |
HIGH
|
gurgens
|
gurgens_ultimate_forum
|
Gurgens (GASoft) Ultimate Forum 1.0 stores the db/Genid.dat database file under the web document root with insufficient access control, which allows remote attackers to obtain and decrypt usernames a…
|
NVD-CWE-Other
|
CVE-2005-1648
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347056
|
7.5 |
HIGH
|
woppoware
|
postmaster
|
Directory traversal vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the wmm param…
|
NVD-CWE-Other
|
CVE-2005-1651
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347057
|
7.5 |
HIGH
|
woppoware
|
postmaster
|
message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to bypass authentication by modifying the email parameter.
|
NVD-CWE-Other
|
CVE-2005-1652
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347058
|
6.8 |
MEDIUM
|
woppoware
|
postmaster
|
Cross-site scripting (XSS) vulnerability in message.htm for Woppoware PostMaster 4.2.2 (build 3.2.5) allows remote attackers to inject arbitrary web script or HTML via the email parameter.
|
NVD-CWE-Other
|
CVE-2005-1653
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347059
|
5.0 |
MEDIUM
|
aol
|
instant_messenger
|
AOL Instant Messenger 5.5.x and earlier allows remote attackers to cause a denial of service (client crash) via an invalid smiley icon location in the sml parameter of a font tag.
|
NVD-CWE-Other
|
CVE-2005-1655
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347060
|
5.0 |
MEDIUM
|
mercur
|
mercur_messaging
|
Mercur Messaging 2005 SP2 allows remote attackers to read the source code of .ctml files via a URL with a trailing hex-encoded space ("%20").
|
NVD-CWE-Other
|
CVE-2005-1656
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347061
|
7.5 |
HIGH
|
mercur
|
mercur_messaging
|
Multiple directory traversal vulnerabilities in Mercur Messaging 2005 SP2 allow remote attackers to perform unauthorized file operations via the Folder.Id parameter to (1) deletefolder.ctml, (2) dele…
|
NVD-CWE-Other
|
CVE-2005-1657
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347062
|
5.0 |
MEDIUM
|
myserver
|
myserver
|
Directory traversal vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to list the parent directory of the web root via a URL with a "..." (triple dot).
|
NVD-CWE-Other
|
CVE-2005-1658
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347063
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in filemanager.cpp in MyServer 0.8 allows remote attackers to inject arbitrary Javascript via a URL with a "..." (triple dot) followed by an onmouseover even…
|
NVD-CWE-Other
|
CVE-2005-1659
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347064
|
5.0 |
MEDIUM
|
jeuce
|
jeuce_personal_web_server
|
Jeuce Personal Webserver 2.13 allows remote attackers to cause a denial of service (server crash) via a long GET request, possibly triggering a buffer overflow.
|
NVD-CWE-Other
|
CVE-2005-1661
|
2008-09-6 05:49 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347065
|
4.3 |
MEDIUM
|
ubertec
|
help_center_live
|
Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message …
|
NVD-CWE-Other
|
CVE-2005-1672
|
2008-09-6 05:49 |
2005-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347066
|
7.5 |
HIGH
|
ubertec
|
help_center_live
|
Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter…
|
NVD-CWE-Other
|
CVE-2005-1673
|
2008-09-6 05:49 |
2005-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347067
|
4.6 |
MEDIUM
|
groove
|
groove_workspace virtual_office
|
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 installs the client installation directories with insecure EVERYBODY permissions, whic…
|
NVD-CWE-Other
|
CVE-2005-1675
|
2008-09-6 05:49 |
2005-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347068
|
6.8 |
MEDIUM
|
groove
|
groove_workspace virtual_office
|
Multiple cross-site scripting (XSS) vulnerabilities in Groove Mobile Workspace in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allo…
|
NVD-CWE-Other
|
CVE-2005-1676
|
2008-09-6 05:49 |
2005-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347069
|
7.5 |
HIGH
|
groove
|
groove_workspace virtual_office
|
Unknown vulnerability in Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 allows remote attackers to bypass restrictions on COM objects.
|
NVD-CWE-Other
|
CVE-2005-1677
|
2008-09-6 05:49 |
2005-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347070
|
2.6 |
LOW
|
groove
|
groove_workspace virtual_office
|
Groove Virtual Office before 3.1 build 2338, before 3.1a build 2364, and Groove Workspace before 2.5n build 1871 does not properly display file extensions on attached or embedded files in a compound …
|
NVD-CWE-Other
|
CVE-2005-1678
|
2008-09-6 05:49 |
2005-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347071
|
5.0 |
MEDIUM
|
sap
|
sap_r_3
|
Directory traversal vulnerability in Internet Graphics Server in SAP before 6.40 Patch 11 allows remote attackers to read arbitrary files via ".." sequences in an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2005-1691
|
2008-09-6 05:49 |
2005-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347072
|
7.5 |
HIGH
|
mailscanner
|
mailscanner
|
Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers to bypass virus detection.
|
NVD-CWE-Other
|
CVE-2005-1706
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347073
|
7.5 |
HIGH
|
mailscanner
|
mailscanner
|
The vendor has released a fixed version (4.42.2)
|
NVD-CWE-Other
|
CVE-2005-1706
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347074
|
7.5 |
HIGH
|
clam_anti-virus gibraltar squid
|
clamav gibraltar_firewall squid
|
Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses f…
|
NVD-CWE-Other
|
CVE-2005-1711
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347075
|
7.5 |
HIGH
|
sy9
|
serendipity
|
Unknown vulnerability in Serendipity 0.8, when used with multiple authors, allows unprivileged authors to upload arbitrary media files.
|
NVD-CWE-Other
|
CVE-2005-1712
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347076
|
4.3 |
MEDIUM
|
s9y
|
serendipity
|
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins.
|
NVD-CWE-Other
|
CVE-2005-1713
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347077
|
4.3 |
MEDIUM
|
ej3
|
topo
|
Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (…
|
NVD-CWE-Other
|
CVE-2005-1715
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347078
|
5.0 |
MEDIUM
|
ej3
|
topo
|
TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client I…
|
NVD-CWE-Other
|
CVE-2005-1716
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347079
|
5.0 |
MEDIUM
|
zyxel
|
prestige_650r-31
|
ZyXEL Prestige 650R-31 router running ZyNOS FW v3.40(KO.1) allows remote attackers to cause a denial of service (CPU consumption and network loss) via crafted fragmented IP packets.
|
NVD-CWE-Other
|
CVE-2005-1717
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347080
|
5.0 |
MEDIUM
|
ls_games
|
war_times
|
Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname.
|
NVD-CWE-Other
|
CVE-2005-1718
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347081
|
7.5 |
HIGH
|
alwil
|
avast_antivirus
|
Unknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.
|
NVD-CWE-Other
|
CVE-2005-1719
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347082
|
2.1 |
LOW
|
apple
|
afp_server
|
AFP Server for Mac OS X 10.4.1, when using an ACL enabled volume, does not properly remove an ACL when a file is copied to a directory that does not use ACLs, which will override the POSIX file permi…
|
NVD-CWE-Other
|
CVE-2005-1720
|
2008-09-6 05:49 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347083
|
7.5 |
HIGH
|
apple
|
afp_server
|
Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-1721
|
2008-09-6 05:49 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347084
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.
|
NVD-CWE-Other
|
CVE-2005-1722
|
2008-09-6 05:49 |
2005-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347085
|
7.5 |
HIGH
|
apple
|
mac_os_x_server
|
LaunchServices in Apple Mac OS X 10.4.x up to 10.4.1 does not properly mark file extensions and MIME types as unsafe if an Apple Uniform Type Identifier (UTI) is not created when the type is added to…
|
NVD-CWE-Other
|
CVE-2005-1723
|
2008-09-6 05:49 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347086
|
7.5 |
HIGH
|
apple
|
mac_os_x_server
|
NFS on Apple Mac OS X 10.4.x up to 10.4.1 does not properly obey the -network or -mask flags for a filesystem and exports it to everyone, which allows remote attackers to bypass intended access restr…
|
NVD-CWE-Other
|
CVE-2005-1724
|
2008-09-6 05:49 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347087
|
3.7 |
LOW
|
apple
|
mac_os_x_server
|
Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthoriz…
|
NVD-CWE-Other
|
CVE-2005-1727
|
2008-09-6 05:49 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347088
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials.
|
NVD-CWE-Other
|
CVE-2005-1728
|
2008-09-6 05:49 |
2005-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347089
|
5.0 |
MEDIUM
|
novell
|
edirectory
|
Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.
|
NVD-CWE-Other
|
CVE-2005-1729
|
2008-09-6 05:49 |
2005-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347090
|
7.5 |
HIGH
|
electricmonk
|
proms
|
Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1734
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347091
|
4.3 |
MEDIUM
|
electricmonk
|
proms
|
Multiple cross-site scripting (XSS) vulnerabilities in PROMS before 0.11 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1735
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347092
|
7.5 |
HIGH
|
electricmonk
|
proms
|
PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.
|
NVD-CWE-Other
|
CVE-2005-1736
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347093
|
10.0 |
HIGH
|
iron_bars_shell
|
iron_bars_shell
|
Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to "access files outside the home directory" and possibly execute arbitrar…
|
NVD-CWE-Other
|
CVE-2005-1738
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347094
|
10.0 |
HIGH
|
iron_bars_shell
|
iron_bars_shell
|
Fixed in version 0.3 d
|
NVD-CWE-Other
|
CVE-2005-1738
|
2008-09-6 05:49 |
2005-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347095
|
7.5 |
HIGH
|
pavuk
|
pavuk
|
Multiple buffer overflows in Pavuk before 0.9.32 have unknown attack vectors and impact.
|
NVD-CWE-Other
|
CVE-2005-1035
|
2008-09-6 05:48 |
2005-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347096
|
10.0 |
HIGH
|
ibm
|
aix
|
Unknown vulnerability in AIX 5.3.0, when configured as an NIS client, allows remote attackers to gain root privileges.
|
NVD-CWE-Other
|
CVE-2005-1037
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347097
|
3.7 |
LOW
|
gnu
|
coreutils
|
Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.
|
NVD-CWE-Other
|
CVE-2005-1039
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347098
|
7.2 |
HIGH
|
novell
|
linux_desktop
|
Multiple unknown vulnerabilities in netapplet in Novell Linux Desktop 9 allow local users to gain root privileges, related to "User input [being] passed to network scripts without verification."
|
NVD-CWE-Other
|
CVE-2005-1040
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347099
|
5.0 |
MEDIUM
|
logwatch redhat
|
logwatch enterprise_linux linux_advanced_workstation
|
The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expre…
|
NVD-CWE-Other
|
CVE-2005-1061
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347100
|
5.0 |
MEDIUM
|
kerio
|
kerio_mailserver personal_firewall winroute_firewall
|
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consu…
|
NVD-CWE-Other
|
CVE-2005-1063
|
2008-09-6 05:48 |
2005-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|