|
347151
|
4.3 |
MEDIUM
|
woltlab
|
burning_board
|
Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid parameter.
|
NVD-CWE-Other
|
CVE-2005-1327
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347152
|
4.9 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled…
|
CWE-20
Improper Input Validation
|
CVE-2005-1330
|
2008-09-6 05:48 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347153
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to …
|
NVD-CWE-Other
|
CVE-2005-1332
|
2008-09-6 05:48 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347154
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-1333
|
2008-09-6 05:48 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347155
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
|
NVD-CWE-Other
|
CVE-2005-1335
|
2008-09-6 05:48 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347156
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.
|
NVD-CWE-Other
|
CVE-2005-1336
|
2008-09-6 05:48 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347157
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
|
NVD-CWE-Other
|
CVE-2005-1337
|
2008-09-6 05:48 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347158
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.
|
NVD-CWE-Other
|
CVE-2005-1338
|
2008-09-6 05:48 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347159
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
|
NVD-CWE-Other
|
CVE-2005-1339
|
2008-09-6 05:48 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347160
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.
|
NVD-CWE-Other
|
CVE-2005-1340
|
2008-09-6 05:48 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347161
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
|
NVD-CWE-Other
|
CVE-2005-1343
|
2008-09-6 05:48 |
2005-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347162
|
2.6 |
LOW
|
symantec
|
antivirus_scan_engine mail_security norton_antivirus norton_internet_security norton_system_works symav_filter_domino_nt web_security
|
Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domin…
|
NVD-CWE-Other
|
CVE-2005-1346
|
2008-09-6 05:48 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347163
|
4.3 |
MEDIUM
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.
|
NVD-CWE-Other
|
CVE-2005-0682
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347164
|
7.5 |
HIGH
|
mlterm
|
mlterm
|
Integer overflow in mlterm 2.5.0 through 2.9.1, with gdk-pixbuf support enabled, allows remote attackers to execute arbitrary code via a large image file that is used as a background.
|
NVD-CWE-Other
|
CVE-2005-0686
|
2008-09-6 05:47 |
2005-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347165
|
7.5 |
HIGH
|
hashcash
|
hashcash
|
Format string vulnerability in Hashcash 1.16 allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via format string specifiers in a reply addr…
|
NVD-CWE-Other
|
CVE-2005-0687
|
2008-09-6 05:47 |
2005-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347166
|
7.5 |
HIGH
|
jowood_productions
|
chaser
|
Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.
|
NVD-CWE-Other
|
CVE-2005-0693
|
2008-09-6 05:47 |
2005-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347167
|
7.5 |
HIGH
|
brt
|
copperexport
|
SQL injection vulnerability in the process_picture function xp_publish.php in CopperExport 0.2.1 allows remote attackers to execute arbitrary SQL commands, possibly via the (1) title, (2) caption, or…
|
NVD-CWE-Other
|
CVE-2005-0697
|
2008-09-6 05:47 |
2005-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347168
|
4.6 |
MEDIUM
|
jason_hines
|
phpweblog
|
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the (1) G_PATH parameter to init.inc.php or the (2) PATH para…
|
NVD-CWE-Other
|
CVE-2005-0698
|
2008-09-6 05:47 |
2005-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347169
|
5.0 |
MEDIUM
|
aztek_forum
|
aztek_forum
|
The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the ATK_ADMIN cookie.
|
NVD-CWE-Other
|
CVE-2005-0700
|
2008-09-6 05:47 |
2005-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347170
|
5.0 |
MEDIUM
|
phpmyfaq
|
phpmyfaq
|
SQL injection vulnerability in phpMyFAQ 1.4 and 1.5 allows remote attackers to add FAQ records to the database via the username field in forum messages.
|
NVD-CWE-Other
|
CVE-2005-0702
|
2008-09-6 05:47 |
2005-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347171
|
5.0 |
MEDIUM
|
xerox
|
workcentre_165 workcentre_175 workcentre_2128 workcentre_2636 workcentre_32_color workcentre_35 workcentre_3545 workcentre_40_color workcentre_45 workcentre_55 workcentr…
|
Xerox MicroServer Web Server for various WorkCentre products including M35/M45/M55 2.028.11.000 through 2.97.20.032 and 4.84.16.000 through 4.97.20.032, Pro 35/45/55 3.028.11.000 through 3.97.20.032,…
|
NVD-CWE-Other
|
CVE-2005-0703
|
2008-09-6 05:47 |
2005-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347172
|
4.6 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0713
|
2008-09-6 05:47 |
2005-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347173
|
2.1 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local users to read the contents of a Drop Box.
|
NVD-CWE-Other
|
CVE-2005-0715
|
2008-09-6 05:47 |
2005-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347174
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH enviro…
|
NVD-CWE-Other
|
CVE-2005-0716
|
2008-09-6 05:47 |
2005-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347175
|
7.5 |
HIGH
|
yahoo
|
messenger
|
Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.
|
NVD-CWE-Other
|
CVE-2005-0737
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347176
|
5.0 |
MEDIUM
|
openbsd
|
openbsd
|
The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments t…
|
NVD-CWE-Other
|
CVE-2005-0740
|
2008-09-6 05:47 |
2005-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347177
|
4.3 |
MEDIUM
|
yabb
|
yabb
|
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a usersrecentposts action.
|
NVD-CWE-Other
|
CVE-2005-0741
|
2008-09-6 05:47 |
2005-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347178
|
4.6 |
MEDIUM
|
utstarcom
|
ian-02ex_voip_ata
|
UTStarcom iAN-02EX VoIP Analog Terminal Adaptor (ATA) allows local users to bypass ATA access restrictions by dialing "*#26845#" and causing a device reset.
|
NVD-CWE-Other
|
CVE-2005-0745
|
2008-09-6 05:47 |
2005-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347179
|
5.0 |
MEDIUM
|
applyyourself
|
i-class
|
ApplyYourself i-Class allows remote attackers to obtain sensitive information about their own applications by reusing the hidden ID field, as demonstrated using the id parameter to ApplicantDecision.…
|
NVD-CWE-Other
|
CVE-2005-0747
|
2008-09-6 05:47 |
2005-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347180
|
4.6 |
MEDIUM
|
midnight_commander
|
midnight_commander
|
Buffer overflow in Midnight Commander (mc) 4.5.55 and earlier may allow attackers to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0763
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347181
|
7.5 |
HIGH
|
marc_lehmann
|
rxvt-unicode
|
Buffer overflow in command.C for rxvt-unicode before 5.3 allows remote attackers to execute arbitrary code via a crafted file containing long escape sequences.
|
NVD-CWE-Other
|
CVE-2005-0764
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347182
|
7.5 |
HIGH
|
notify_technology
|
notifylink
|
NotifyLink, when configured for client key retrieval, allows remote attackers to obtain AES keys via a direct request to /hwp/get.asp, then uses a weak encryption scheme (fixed byte reordering) to pr…
|
NVD-CWE-Other
|
CVE-2005-0809
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347183
|
7.5 |
HIGH
|
notify_technology
|
notifylink
|
SQL injection vulnerability in NotifyLink before 3.0 allows remote attackers to execute arbitrary SQL commands via the URL.
|
NVD-CWE-Other
|
CVE-2005-0810
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347184
|
4.6 |
MEDIUM
|
notify_technology
|
notifylink
|
The web interface in NotifyLink 3.0 does not properly restrict access to functions that have been disabled in the GUI, which allows remote authenticated users to bypass intended restrictions via a di…
|
NVD-CWE-Other
|
CVE-2005-0811
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347185
|
5.0 |
MEDIUM
|
notify_technology
|
notifylink
|
The web interface in NotifyLink 3.0 displays passwords in cleartext on the administrative page, which could allow remote attackers or local users to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-0812
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347186
|
5.0 |
MEDIUM
|
initial_redirect
|
initial_redirect_squid_proxy_plug-in
|
Buffer overflow in Initial Redirect (ir) Squid Proxy Plug-In 0.1 and 0.2 may allow attackers to cause a denial of service and execute arbitrary code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-0813
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347187
|
5.0 |
MEDIUM
|
novell
|
netware
|
The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.
|
NVD-CWE-Other
|
CVE-2005-0819
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347188
|
5.0 |
MEDIUM
|
-
|
-
|
Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database…
|
NVD-CWE-Other
|
CVE-2005-0820
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347189
|
2.1 |
LOW
|
citrix
|
metaframe_password_manager
|
Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is…
|
NVD-CWE-Other
|
CVE-2005-0822
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347190
|
7.5 |
HIGH
|
lgames
|
ltris
|
Buffer overflow in LTris before 1.0.10 allows local users to execute arbitrary code via a crafted highscores file.
|
NVD-CWE-Other
|
CVE-2005-0825
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347191
|
7.5 |
HIGH
|
xzabite
|
dyndnsupdate
|
Multiple buffer overflows in Xzabite DYNDNSUpdate 0.6.15 and earlier, including the ipcheck function in dyndnsupdate.c, allow remote attackers who spoof a dyndns.org server to execute arbitrary code …
|
NVD-CWE-Other
|
CVE-2005-0830
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347192
|
5.0 |
MEDIUM
|
php-post
|
php-post_web_forum
|
PHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.
|
NVD-CWE-Other
|
CVE-2005-0831
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347193
|
7.5 |
HIGH
|
belkin
|
belkin_54g_wireless_router
|
Belkin 54G (F5D7130) wireless router allows remote attackers to access restricted resources by sniffing URIs from UPNP datagrams, then accessing those URIs, which do not require authentication.
|
NVD-CWE-Other
|
CVE-2005-0833
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347194
|
5.0 |
MEDIUM
|
-
|
-
|
Belkin 54G (F5D7130) wireless router enables SNMP by default in a manner that allows remote attackers to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2005-0834
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347195
|
5.0 |
MEDIUM
|
belkin
|
54g_wireless_router
|
The SNMP service in the Belkin 54G (F5D7130) wireless router allows remote attackers to cause a denial of service via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-0835
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347196
|
5.0 |
MEDIUM
|
funlabs
|
4x4_off-road_adventure_iii cabelas_big_game_hunter_2004_season cabelas_big_game_hunter_2005 cabelas_dangerous_hunts cabelas_deer_hunt_2005_season revolution secret_service_in_harms_…
|
Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote att…
|
NVD-CWE-Other
|
CVE-2005-0849
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347197
|
2.1 |
LOW
|
-
|
-
|
Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Pyth…
|
NVD-CWE-Other
|
CVE-2005-0852
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347198
|
10.0 |
HIGH
|
coolforum
|
coolforum
|
CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.p…
|
NVD-CWE-Other
|
CVE-2005-0855
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347199
|
7.5 |
HIGH
|
coolforum
|
coolforum
|
CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability.
|
NVD-CWE-Other
|
CVE-2005-0856
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347200
|
7.5 |
HIGH
|
the_rusted_gate
|
trg_news
|
PHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter to (1) article.php, (2) authorall.php, (3) comment.php, (4) …
|
NVD-CWE-Other
|
CVE-2005-0860
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|