|
347101
|
2.1 |
LOW
|
novell
|
linux_desktop
|
tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.
|
NVD-CWE-Other
|
CVE-2005-1065
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347102
|
1.2 |
LOW
|
university_of_washington
|
pine
|
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2005-1066
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347103
|
7.5 |
HIGH
|
access_user_class
|
access_user_class
|
Vulnerability in Access_user Class before 1.75 allows local users to gain access as other users via the password "new".
|
NVD-CWE-Other
|
CVE-2005-1067
|
2008-09-6 05:48 |
2005-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347104
|
4.3 |
MEDIUM
|
punbb
|
punbb
|
Cross-site scripting (XSS) vulnerability in PunBB before 1.2.5 allows remote attackers to inject arbitrary web script or HTML.
|
NVD-CWE-Other
|
CVE-2005-1072
|
2008-09-6 05:48 |
2005-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347105
|
4.3 |
MEDIUM
|
webct
|
webct
|
Cross-site scripting (XSS) vulnerability in the discussion board functionality for WebCT Campus Edition 4.1 allows remote attackers to inject arbitrary web script or HTML via the message field.
|
NVD-CWE-Other
|
CVE-2005-1076
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347106
|
5.0 |
MEDIUM
|
aewebworks
|
aedating
|
index.php in aeDating 3.2 allows remote attackers to include arbitrary files via the skin parameter.
|
NVD-CWE-Other
|
CVE-2005-1083
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347107
|
7.5 |
HIGH
|
aewebworks
|
aedating
|
SQL injection vulnerability in sdating.php in aeDating 3.2 allows remote attackers to execute arbitrary SQL commands files via the event parameter.
|
NVD-CWE-Other
|
CVE-2005-1084
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347108
|
4.3 |
MEDIUM
|
-
|
-
|
Cross-site scripting (XSS) vulnerability in the control panel in aeDating 3.2 allows remote attackers to inject arbitrary web script or HTML.
|
NVD-CWE-Other
|
CVE-2005-1085
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347109
|
5.0 |
MEDIUM
|
dc\+\+
|
dc\+\+
|
Unknown vulnerability in DC++ before 0.674 allows attackers to append data to arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-1089
|
2008-09-6 05:48 |
2005-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347110
|
7.5 |
HIGH
|
-
|
-
|
Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.
|
NVD-CWE-Other
|
CVE-2005-1091
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347111
|
7.2 |
HIGH
|
light_speed_technology
|
deluxeftp
|
Lightspeed DeluxeFTP 6.01 stores usernames and passwords in plaintext in sites.xml, which is world-readable, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-1092
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347112
|
4.6 |
MEDIUM
|
rebrand
|
p2p_share_spy
|
Rebrand P2P Share Spy 2.2 stores the user password in plaintext in the txtPassword value in the registry, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-1097
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347113
|
7.2 |
HIGH
|
mcafee
|
internet_security_suite
|
McAfee Internet Security Suite 2005 uses insecure default ACLs for installed files, which allows local users to gain privileges or disable protection by modifying certain files.
|
NVD-CWE-Other
|
CVE-2005-1107
|
2008-09-6 05:48 |
2005-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347114
|
2.1 |
LOW
|
todd_miller
|
sudo
|
Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-1119
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347115
|
5.1 |
MEDIUM
|
avaya
|
libsafe
|
Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit other vulnerabilities before the _libsafe_die func…
|
NVD-CWE-Other
|
CVE-2005-1125
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347116
|
7.5 |
HIGH
|
virtual_hosting_control_system
|
virtual_hosting_control_system
|
Multiple SQL injection vulnerabilities in VHCS 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via certain inputs from HTTP POST queries.
|
NVD-CWE-Other
|
CVE-2005-1128
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347117
|
10.0 |
HIGH
|
symantec_veritas
|
i3_focalpoint_server
|
Unknown vulnerability in Veritas i3 Focalpoint Server 7.1 and earlier has unknown attack vectors and unknown but "critical" impact.
|
NVD-CWE-Other
|
CVE-2005-1131
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347118
|
5.0 |
MEDIUM
|
kerio
|
kerio_mailserver
|
Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain e-mail messages.
|
NVD-CWE-Other
|
CVE-2005-1138
|
2008-09-6 05:48 |
2005-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347119
|
4.3 |
MEDIUM
|
mywebland
|
mybloggie
|
Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.
|
NVD-CWE-Other
|
CVE-2005-1140
|
2008-09-6 05:48 |
2005-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347120
|
4.3 |
MEDIUM
|
easyphpcalendar
|
easyphpcalendar
|
Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.
|
NVD-CWE-Other
|
CVE-2005-1143
|
2008-09-6 05:48 |
2005-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347121
|
5.0 |
MEDIUM
|
easyphpcalendar
|
easyphpcalendar
|
popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.
|
NVD-CWE-Other
|
CVE-2005-1144
|
2008-09-6 05:48 |
2005-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347122
|
5.0 |
MEDIUM
|
easyphpcalendar
|
easyphpcalendar
|
Version 6.2.8 and above are fixed.
|
NVD-CWE-Other
|
CVE-2005-1144
|
2008-09-6 05:48 |
2005-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347123
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
|
NVD-CWE-Other
|
CVE-2005-1149
|
2008-09-6 05:48 |
2005-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347124
|
5.0 |
MEDIUM
|
sun
|
java_system_web_server
|
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).
|
NVD-CWE-Other
|
CVE-2005-1150
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347125
|
7.2 |
HIGH
|
debian
|
qpopper
|
qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.
|
NVD-CWE-Other
|
CVE-2005-1151
|
2008-09-6 05:48 |
2005-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347126
|
2.1 |
LOW
|
debian
|
qpopper
|
popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.
|
NVD-CWE-Other
|
CVE-2005-1152
|
2008-09-6 05:48 |
2005-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347127
|
4.3 |
MEDIUM
|
jaws
|
jaws
|
Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrary web script or HTML via the (1) term or (2) description.
|
NVD-CWE-Other
|
CVE-2005-1231
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347128
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb-auction
|
auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2005-1235
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347129
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb-auction
|
Fixed updated version on http://www.phpbb-auction.com/
|
NVD-CWE-Other
|
CVE-2005-1235
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347130
|
7.5 |
HIGH
|
duware
|
duportal
|
Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp or search.asp, (2)…
|
NVD-CWE-Other
|
CVE-2005-1236
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347131
|
10.0 |
HIGH
|
vladislav_bogdanov
|
snmppd
|
Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format strin…
|
NVD-CWE-Other
|
CVE-2005-1246
|
2008-09-6 05:48 |
2005-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347132
|
5.0 |
MEDIUM
|
novell
|
nsure_audit
|
webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exp…
|
NVD-CWE-Other
|
CVE-2005-1247
|
2008-09-6 05:48 |
2004-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347133
|
7.5 |
HIGH
|
ipswitch
|
whatsup
|
SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the…
|
NVD-CWE-Other
|
CVE-2005-1250
|
2008-09-6 05:48 |
2005-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347134
|
10.0 |
HIGH
|
mysql
|
maxdb
|
Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a …
|
NVD-CWE-Other
|
CVE-2005-1274
|
2008-09-6 05:48 |
2005-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347135
|
5.0 |
MEDIUM
|
ethereal_group
|
ethereal
|
Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.
|
NVD-CWE-Other
|
CVE-2005-1281
|
2008-09-6 05:48 |
2005-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347136
|
7.5 |
HIGH
|
inter7
|
sqwebmail
|
SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.
|
NVD-CWE-Other
|
CVE-2005-1308
|
2008-09-6 05:48 |
2005-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347137
|
4.3 |
MEDIUM
|
eaden_mckee
|
bblog
|
Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.
|
NVD-CWE-Other
|
CVE-2005-1309
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347138
|
7.5 |
HIGH
|
eaden_mckee
|
bblog
|
SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
|
NVD-CWE-Other
|
CVE-2005-1310
|
2008-09-6 05:48 |
2005-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347139
|
4.3 |
MEDIUM
|
yappa-ng
|
yappa-ng
|
Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1311
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347140
|
7.5 |
HIGH
|
yappa-ng
|
yappa-ng
|
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1312
|
2008-09-6 05:48 |
2005-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347141
|
4.3 |
MEDIUM
|
horde
|
passwd
|
Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1313
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347142
|
4.3 |
MEDIUM
|
horde
|
kronolith
|
Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1314
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347143
|
4.3 |
MEDIUM
|
horde
|
turba
|
Cross-site scripting (XSS) vulnerability in Horde Turba module before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1315
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347144
|
6.8 |
MEDIUM
|
horde
|
chora
|
Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1317
|
2008-09-6 05:48 |
2005-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347145
|
4.3 |
MEDIUM
|
horde
|
forwards
|
Cross-site scripting (XSS) vulnerability in Horde Forwards E-Mail Forwarding Manager before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1318
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347146
|
4.3 |
MEDIUM
|
horde
|
imp
|
Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1319
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347147
|
4.3 |
MEDIUM
|
horde
|
mnemo
|
Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1320
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347148
|
4.3 |
MEDIUM
|
horde
|
vaction
|
Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1321
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347149
|
4.3 |
MEDIUM
|
horde
|
nag
|
Cross-site scripting (XSS) vulnerability in Horde Nag Task List Manager before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1322
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347150
|
5.0 |
MEDIUM
|
voodoo_circle
|
voodoo_circle
|
Buffer overflow in VooDoo cIRCle BOTNET before 1.0.33 allows remote authenticated attackers to cause a denial of service (client crash) via a crafted packet.
|
NVD-CWE-Other
|
CVE-2005-1326
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|