|
347201
|
5.0 |
MEDIUM
|
securecomputing
|
samsung_adsl_modem
|
The Boa web server, as used in Samsung ADSL Modem SMDK8947v1.2 and possibly other products, allows remote attackers to read arbitrary files via a full pathname in the HTTP request.
|
NVD-CWE-Other
|
CVE-2005-0864
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347202
|
7.5 |
HIGH
|
securecomputing
|
samsung_adsl_modem
|
Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP request to adsl.cgi.
|
NVD-CWE-Other
|
CVE-2005-0865
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347203
|
4.3 |
MEDIUM
|
invision_power_services
|
invision_board
|
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an HTTP POST request.
|
NVD-CWE-Other
|
CVE-2005-0886
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347204
|
4.3 |
MEDIUM
|
dream4
|
koobi_cms
|
Cross-site scripting (XSS) vulnerability in index.php for Dream4 Koobi CMS 4.2.3 allows remote attackers to inject arbitrary web script or HTML via the area parameter.
|
NVD-CWE-Other
|
CVE-2005-0889
|
2008-09-6 05:47 |
2005-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347205
|
7.5 |
HIGH
|
dream4
|
koobi_cms
|
SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the area parameter.
|
NVD-CWE-Other
|
CVE-2005-0890
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347206
|
7.5 |
HIGH
|
instance_four sacred ubi_soft
|
tincat sacred the_settlersheritage_of_kings
|
Buffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The Settlers: Heritage of Kings, allows remote attackers to execute a…
|
NVD-CWE-Other
|
CVE-2005-0906
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347207
|
7.5 |
HIGH
|
valdersoft
|
shopping_cart
|
Multiple SQL injection vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to category.php, (2) the id parameter to item.…
|
NVD-CWE-Other
|
CVE-2005-0907
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347208
|
4.3 |
MEDIUM
|
valdersoft
|
valdersoft_shopping_cart
|
Multiple cross-site scripting (XSS) vulnerabilities in Valdersoft Shopping Cart 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter to index.php or (2) the se…
|
NVD-CWE-Other
|
CVE-2005-0908
|
2008-09-6 05:47 |
2005-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347209
|
4.3 |
MEDIUM
|
e-xoops
|
e-xoops
|
Multiple cross-site scripting (XSS) vulnerabilities in exoops allow remote attackers to inject arbitrary web script or HTML via (1) the sortdays parameter to viewforum.php or (2) the viewcat paramete…
|
NVD-CWE-Other
|
CVE-2005-0910
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347210
|
7.5 |
HIGH
|
e-xoops
|
e-xoops
|
Multiple SQL injection vulnerabilities in exoops may allow remote attackers to execute arbitrary SQL commands via (1) the viewcat parameter to index.php or (2) the artid parameter in the viewarticle …
|
NVD-CWE-Other
|
CVE-2005-0911
|
2008-09-6 05:47 |
2005-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347211
|
7.5 |
HIGH
|
deplate
|
deplate
|
Unknown vulnerabilities in deplate before 0.7.2 have unknown impact, possibly involving elements.rb.
|
NVD-CWE-Other
|
CVE-2005-0912
|
2008-09-6 05:47 |
2005-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347212
|
4.3 |
MEDIUM
|
cpg-nuke
|
cpg_dragonfly_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in CPG Dragonfly 9.0.2.0 allow remote attackers to inject arbitrary web script or HTML via (1) the profile parameter to index.php or (2) the cat pa…
|
NVD-CWE-Other
|
CVE-2005-0914
|
2008-09-6 05:47 |
2005-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347213
|
7.5 |
HIGH
|
webmasters-debutants
|
wd_guestbook
|
Webmasters-Debutants WD Guestbook 2.8 allows remote attackers to bypass authentication and perform certain administrator actions via a direct HTTP POST request to (1) ajout_admin2.php or (2) suppr.ph…
|
NVD-CWE-Other
|
CVE-2005-0915
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347214
|
2.1 |
LOW
|
linux
|
linux_kernel
|
AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_qu…
|
NVD-CWE-Other
|
CVE-2005-0916
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347215
|
7.5 |
HIGH
|
powerdev
|
encapsbb
|
PHP remote file inclusion vulnerability in index_header.php for EncapsBB 0.3.2_fixed, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the root parameter.
|
NVD-CWE-Other
|
CVE-2005-0917
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347216
|
7.5 |
HIGH
|
-
|
-
|
Multiple SQL injection vulnerabilities in Bugtracker.NET 2.0.1 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-0920
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347217
|
4.6 |
MEDIUM
|
microsoft
|
outlook_connector
|
Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.
|
NVD-CWE-Other
|
CVE-2005-0921
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347218
|
5.0 |
MEDIUM
|
symantec
|
norton_antivirus norton_internet_security norton_system_works
|
Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial…
|
NVD-CWE-Other
|
CVE-2005-0922
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347219
|
2.1 |
LOW
|
symantec
|
norton_antivirus norton_internet_security norton_system_works
|
The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denia…
|
NVD-CWE-Other
|
CVE-2005-0923
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347220
|
10.0 |
HIGH
|
web-app.org
|
webapp
|
Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences.
|
NVD-CWE-Other
|
CVE-2005-0927
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347221
|
4.3 |
MEDIUM
|
chatness
|
chatness
|
Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message paramete…
|
NVD-CWE-Other
|
CVE-2005-0930
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347222
|
7.5 |
HIGH
|
jimmy
|
the_includer
|
PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code.
|
NVD-CWE-Other
|
CVE-2005-0931
|
2008-09-6 05:47 |
2005-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347223
|
4.3 |
MEDIUM
|
wackowiki
|
wackowiki
|
Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-0934
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347224
|
7.5 |
HIGH
|
yepyep
|
mtftpd
|
Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path.
|
NVD-CWE-Other
|
CVE-2005-0959
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347225
|
5.0 |
MEDIUM
|
openbsd
|
openbsd
|
Multiple vulnerabilities in the SACK functionality in (1) tcp_input.c and (2) tcp_usrreq.c OpenBSD 3.5 and 3.6 allow remote attackers to cause a denial of service (memory exhaustion or system crash).
|
NVD-CWE-Other
|
CVE-2005-0960
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347226
|
4.3 |
MEDIUM
|
horde
|
application_framework
|
Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.
|
NVD-CWE-Other
|
CVE-2005-0961
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347227
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via craf…
|
NVD-CWE-Other
|
CVE-2005-0969
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347228
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
|
NVD-CWE-Other
|
CVE-2005-0971
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347229
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
|
NVD-CWE-Other
|
CVE-2005-0972
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347230
|
2.1 |
LOW
|
apple
|
mac_os_x
|
Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.
|
NVD-CWE-Other
|
CVE-2005-0973
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347231
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
|
NVD-CWE-Other
|
CVE-2005-0974
|
2008-09-6 05:47 |
2005-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347232
|
5.0 |
MEDIUM
|
apple hmdt omnigroup
|
safari shiira omniweb
|
AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript componen…
|
NVD-CWE-Other
|
CVE-2005-0976
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347233
|
2.1 |
LOW
|
-
|
-
|
Unspecified vulnerability in the Mac OS X kernel before 10.3.8 allows local users to cause a denial of service (temporary hang) via unspecified attack vectors related to the fan control unit (FCU) dr…
|
NVD-CWE-Other
|
CVE-2005-0985
|
2008-09-6 05:47 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347234
|
5.0 |
MEDIUM
|
irc_services
|
nickserv_listlinks
|
Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick.
|
NVD-CWE-Other
|
CVE-2005-0987
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347235
|
2.1 |
LOW
|
-
|
-
|
RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.
|
NVD-CWE-Other
|
CVE-2005-0991
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347236
|
4.3 |
MEDIUM
|
early_impact
|
productcart
|
Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirect…
|
NVD-CWE-Other
|
CVE-2005-0995
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347237
|
4.3 |
MEDIUM
|
asp-dev
|
xm_forum
|
Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via a "javascript:" URL in an IMG tag.
|
NVD-CWE-Other
|
CVE-2005-1008
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347238
|
7.5 |
HIGH
|
iatek
|
siteenable
|
SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
|
NVD-CWE-Other
|
CVE-2005-1011
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347239
|
10.0 |
HIGH
|
mailenable
|
imapd
|
Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
|
NVD-CWE-Other
|
CVE-2005-1015
|
2008-09-6 05:47 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347240
|
7.5 |
HIGH
|
f-secure
|
f-secure_anti-virus f-secure_internet_security f-secure_personal_express internet_gatekeeper
|
Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.
|
NVD-CWE-Other
|
CVE-2005-0350
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347241
|
4.6 |
MEDIUM
|
sco
|
openserver
|
Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2005-0351
|
2008-09-6 05:46 |
2005-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347242
|
5.0 |
MEDIUM
|
microsoft
|
log_sink_class_activex_control
|
The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0360
|
2008-09-6 05:46 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347243
|
4.6 |
MEDIUM
|
awstats
|
awstats
|
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.
|
NVD-CWE-Other
|
CVE-2005-0362
|
2008-09-6 05:46 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347244
|
7.5 |
HIGH
|
awstats
|
awstats
|
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
|
NVD-CWE-Other
|
CVE-2005-0363
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347245
|
4.3 |
MEDIUM
|
mailreader.com
|
mailreader.com
|
Cross-site scripting (XSS) vulnerability in network.cgi in mailreader before 2.3.29 earlier allows remote attackers to inject arbitrary web script or HTML via MIME text/enriched or text/richtext mess…
|
NVD-CWE-Other
|
CVE-2005-0386
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347246
|
2.1 |
LOW
|
remstats
|
remstats
|
remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-0387
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347247
|
7.5 |
HIGH
|
remstats
|
remstats
|
Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."
|
NVD-CWE-Other
|
CVE-2005-0388
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347248
|
7.2 |
HIGH
|
crip
|
crip
|
The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-0393
|
2008-09-6 05:46 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347249
|
5.0 |
MEDIUM
|
kmail kde
|
kmail kde
|
KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
|
NVD-CWE-Other
|
CVE-2005-0404
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347250
|
7.5 |
HIGH
|
sun
|
j2se
|
Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP fil…
|
NVD-CWE-Other
|
CVE-2005-0418
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|