|
357801
|
4.6 |
MEDIUM
|
microsoft
|
windows_2000
|
Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct…
|
NVD-CWE-Other
|
CVE-2005-3173
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357802
|
4.6 |
MEDIUM
|
microsoft
|
windows_2000
|
Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
|
NVD-CWE-Other
|
CVE-2005-3174
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357803
|
7.2 |
HIGH
|
microsoft
|
windows_2000
|
Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to a…
|
NVD-CWE-Other
|
CVE-2005-3175
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357804
|
7.5 |
HIGH
|
microsoft
|
windows_2000
|
Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could mak…
|
NVD-CWE-Other
|
CVE-2005-3176
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357805
|
4.6 |
MEDIUM
|
microsoft
|
windows_2000 windows_2003_server windows_xp
|
CHKDSK in Microsoft Windows 2000 before Update Rollup 1 for SP4, Windows XP, and Windows Server 2003, when running in fix mode, does not properly handle security descriptors if the master file table …
|
NVD-CWE-Other
|
CVE-2005-3177
|
2008-09-6 05:53 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357806
|
2.1 |
LOW
|
-
|
-
|
Multiple unspecified vulnerabilities in Solaris 10 SCTP Socket Option Processing allows local users to cause a denial of service (panic) via unspecified attack vectors.
|
NVD-CWE-Other
|
CVE-2005-3238
|
2008-09-6 05:53 |
2005-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357807
|
6.4 |
MEDIUM
|
gallery_project
|
gallery
|
Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter.
|
NVD-CWE-Other
|
CVE-2005-3251
|
2008-09-6 05:53 |
2005-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357808
|
10.0 |
HIGH
|
nathan_neulinger
|
cgiwrap
|
The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attackers to execute cod…
|
NVD-CWE-Other
|
CVE-2005-3254
|
2008-09-6 05:53 |
2005-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357809
|
5.0 |
MEDIUM
|
-
|
-
|
The (1) cgiwrap and (2) php-cgiwrap packages before 3.9 in Debian GNU/Linux provide access to debugging CGIs under the web document root, which allows remote attackers to obtain sensitive information…
|
NVD-CWE-Other
|
CVE-2005-3255
|
2008-09-6 05:53 |
2005-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357810
|
2.1 |
LOW
|
raphael_bossek
|
yiff_server
|
yiff server (yiff-server) 2.14.2 on Debian GNU/Linux runs as root and does not properly verify ownership of files that it opens, which allows local users to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-3268
|
2008-09-6 05:53 |
2005-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357811
|
7.2 |
HIGH
|
symantec
|
norton_antivirus
|
Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file.
|
NVD-CWE-Other
|
CVE-2005-3270
|
2008-09-6 05:53 |
2005-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357812
|
10.0 |
HIGH
|
hp
|
hp-ux
|
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled w…
|
NVD-CWE-Other
|
CVE-2005-3277
|
2008-09-6 05:53 |
2005-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357813
|
7.2 |
HIGH
|
jan_kybic
|
bitmap_viewer
|
Stack-based buffer overflow in the vgasco_printf function in Jan Kybic BitMap Viewer (BMV) 1.2, when compiled with the M_UNIX flag and running setuid, allows local users to gain privileges via a long…
|
NVD-CWE-Other
|
CVE-2005-3279
|
2008-09-6 05:53 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357814
|
5.0 |
MEDIUM
|
nukefixes
|
nukefixes
|
Directory traversal vulnerability in NukeFixes 3.1 for PHP-Nuke 7.8 allows remote attackers to include arbitrary files via the file parameter.
|
NVD-CWE-Other
|
CVE-2005-3281
|
2008-09-6 05:53 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357815
|
7.5 |
HIGH
|
-
|
-
|
Splatt Forum 3.0 to 3.2 allows remote attackers to bypass authentication via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3282
|
2008-09-6 05:53 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357816
|
7.5 |
HIGH
|
ahnlab
|
myv3 v3net v3pro_2004
|
Multiple buffer overflows in AhnLab V3 AntiVirus V3Pro 2004 before 6.0.0.488, V3Net for Windows Server 6.0 before 6.0.0.488, and MyV3, with compressed file scanning enabled, allow remote attackers to…
|
NVD-CWE-Other
|
CVE-2005-3284
|
2008-09-6 05:53 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357817
|
4.3 |
MEDIUM
|
comersus_open_technologies
|
comersus_backoffice_plus
|
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (…
|
NVD-CWE-Other
|
CVE-2005-3285
|
2008-09-6 05:53 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357818
|
5.0 |
MEDIUM
|
rockliffe
|
mailsite_express
|
Incomplete blacklist vulnerability in Mailsite Express allows remote attackers to upload and possibly execute files via attachments with executable extensions such as ASPX, which are not converted to…
|
NVD-CWE-Other
|
CVE-2005-3287
|
2008-09-6 05:53 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357819
|
2.1 |
LOW
|
ibm
|
aix
|
LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
|
NVD-CWE-Other
|
CVE-2005-3289
|
2008-09-6 05:53 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357820
|
4.6 |
MEDIUM
|
stani
|
stanis_python_editor
|
Stani's Python Editor (SPE) 0.7.5 is installed with world-writable permissions, which allows local users to gain privileges by modifying executable files.
|
NVD-CWE-Other
|
CVE-2005-3291
|
2008-09-6 05:53 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357821
|
4.3 |
MEDIUM
|
xeobook
|
xeobook
|
Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93 allow remote attackers to inject arbitrary web script or HTML via Javascript events in tages such as <b>.
|
NVD-CWE-Other
|
CVE-2005-3292
|
2008-09-6 05:53 |
2005-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357822
|
5.0 |
MEDIUM
|
openvpn
|
openvpn
|
OpenVPN before 2.0.1, when running with "verb 0" and without TLS authentication, does not properly flush the OpenSSL error queue when a client fails certificate authentication to the server and cause…
|
NVD-CWE-Other
|
CVE-2005-2531
|
2008-09-6 05:52 |
2005-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357823
|
5.0 |
MEDIUM
|
openvpn
|
openvpn
|
OpenVPN before 2.0.1 does not properly flush the OpenSSL error queue when a packet can not be decrypted by the server, which allows remote authenticated attackers to cause a denial of service (client…
|
NVD-CWE-Other
|
CVE-2005-2532
|
2008-09-6 05:52 |
2005-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357824
|
2.1 |
LOW
|
openvpn
|
openvpn
|
OpenVPN before 2.0.1, when running in "dev tap" Ethernet bridging mode, allows remote authenticated clients to cause a denial of service (memory exhaustion) via a flood of packets with a large number…
|
NVD-CWE-Other
|
CVE-2005-2533
|
2008-09-6 05:52 |
2005-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357825
|
2.6 |
LOW
|
openvpn
|
openvpn
|
Race condition in OpenVPN before 2.0.1, when --duplicate-cn is not enabled, allows remote attackers to cause a denial of service (server crash) via simultaneous TCP connections from multiple clients …
|
NVD-CWE-Other
|
CVE-2005-2534
|
2008-09-6 05:52 |
2005-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357826
|
7.5 |
HIGH
|
bluez_project
|
bluez
|
security.c in hcid for BlueZ 2.16, 2.17, and 2.18 allows remote attackers to execute arbitrary commands via shell metacharacters in the Bluetooth device name when invoking the PIN helper.
|
NVD-CWE-Other
|
CVE-2005-2547
|
2008-09-6 05:52 |
2005-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357827
|
7.5 |
HIGH
|
novell
|
edirectory
|
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of service (crash) and obtain access to files via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-2551
|
2008-09-6 05:52 |
2005-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357828
|
4.3 |
MEDIUM
|
dvbbs
|
dvbbs
|
Multiple cross-site scripting (XSS) vulnerabilities in DVBBS 7.1 SP2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter to dispbbs.asp, (2) name para…
|
NVD-CWE-Other
|
CVE-2005-2588
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357829
|
7.5 |
HIGH
|
linksys
|
wrt54gs
|
Unknown vulnerability in Linksys WRT54GS wireless router with firmware 4.50.6, with WPA Personal/TKIP authentication enabled, allows remote clients to bypass authentication by connecting without usin…
|
NVD-CWE-Other
|
CVE-2005-2589
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357830
|
5.0 |
MEDIUM
|
apple
|
safari
|
Apple Safari 1.3 (132) on Mac OS X 1.3.9 allows remote attackers to cause a denial of service (crash) via certain Javascript, possibly involving a function that defines a handler for itself within th…
|
NVD-CWE-Other
|
CVE-2005-2594
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357831
|
4.3 |
MEDIUM
|
dada_mail
|
dada_mail
|
Cross-site scripting (XSS) vulnerability in Dada Mail before 2.10 Alpha 1 allows remote attackers to execute arbitrary Javascript via archived messages.
|
NVD-CWE-Other
|
CVE-2005-2595
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357832
|
4.6 |
MEDIUM
|
gallery_project
|
gallery
|
User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries.
|
NVD-CWE-Other
|
CVE-2005-2596
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357833
|
5.0 |
MEDIUM
|
dokeos
|
dokeos
|
Multiple directory traversal vulnerabilities in Dokeos 1.6 and earlier, and possibly Claroline, allow remote attackers to (1) delete arbitrary files or directories via the delete parameter to claroli…
|
NVD-CWE-Other
|
CVE-2005-2598
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357834
|
5.0 |
MEDIUM
|
ilia_alshanetsky
|
fudforum
|
FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter.
|
NVD-CWE-Other
|
CVE-2005-2600
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357835
|
7.5 |
HIGH
|
midicart_software
|
midicart_php_shopping_cart
|
SQL injection vulnerability in MidiCart allows remote attackers to execute arbitrary SQL commands via the code_no parameter to (1) Item_Show.asp or (2) search_list.asp.
|
NVD-CWE-Other
|
CVE-2005-2601
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357836
|
2.6 |
LOW
|
mozilla
|
firefox thunderbird
|
Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.
|
NVD-CWE-Other
|
CVE-2005-2602
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357837
|
6.4 |
MEDIUM
|
omnipilot_software
|
lasso_professional_server
|
Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.
|
NVD-CWE-Other
|
CVE-2005-2605
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357838
|
5.0 |
MEDIUM
|
phpsimplicity
|
simplicity_of_upload
|
PHP file include vulnerability in download.php in PHPSimplicity Simplicity oF Upload before 1.3.1 allows remote attackers to include arbitrary local and remote files via the language parameter and a …
|
NVD-CWE-Other
|
CVE-2005-2607
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357839
|
5.0 |
MEDIUM
|
phpsimplicity
|
simplicity_of_upload
|
Download new version of program at http://www.phpsimplicity.com/scripts.php?id=3.
|
NVD-CWE-Other
|
CVE-2005-2607
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357840
|
4.3 |
MEDIUM
|
safehtml
|
safehtml
|
SafeHTML before 1.3.5 does not properly filter script in UTF-7 and CSS comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks in vulnerable applications that use SafeHT…
|
NVD-CWE-Other
|
CVE-2005-2608
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357841
|
5.0 |
MEDIUM
|
vegadns
|
vegadns
|
index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.
|
NVD-CWE-Other
|
CVE-2005-2609
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357842
|
4.3 |
MEDIUM
|
vegadns
|
vegadns
|
Cross-site scripting (XSS) vulnerability in index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
NVD-CWE-Other
|
CVE-2005-2610
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357843
|
7.5 |
HIGH
|
wordpress
|
wordpress
|
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.
|
NVD-CWE-Other
|
CVE-2005-2612
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357844
|
7.5 |
HIGH
|
crosscom_olicom
|
discuz
|
Discuz! 4.0 rc4 does not properly restrict types of files that are uploaded to the server, which allows remote attackers to execute arbitrary commands via a filename containing ".php.rar" or other mu…
|
NVD-CWE-Other
|
CVE-2005-2614
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357845
|
7.5 |
HIGH
|
eqdkp
|
eqdkp
|
Unknown vulnerability in session.php in EQdkp before 1.3.0 has unknown impact and attack vectors, possibly involving auto_login_id.
|
NVD-CWE-Other
|
CVE-2005-2615
|
2008-09-6 05:52 |
2005-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357846
|
7.5 |
HIGH
|
mutt
|
mutt
|
Buffer overflow in the mutt_decode_xbit function in Handler.c for Mutt 1.5.10 allows remote attackers to execute arbitrary code, possibly due to interactions with libiconv or gettext.
|
NVD-CWE-Other
|
CVE-2005-2642
|
2008-09-6 05:52 |
2005-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357847
|
7.5 |
HIGH
|
isemarket
|
jaguarcontrol
|
Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Jtext field.
|
NVD-CWE-Other
|
CVE-2005-2644
|
2008-09-6 05:52 |
2005-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357848
|
7.5 |
HIGH
|
xerox
|
document_centre_265 document_centre_332 document_centre_340 document_centre_420 document_centre_490 document_centre_535 document_centre_555
|
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to bypass authentication.
|
NVD-CWE-Other
|
CVE-2005-2645
|
2008-09-6 05:52 |
2005-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357849
|
6.4 |
MEDIUM
|
xerox
|
document_centre_220 document_centre_230 document_centre_240 document_centre_255 document_centre_265 document_centre_332 document_centre_340 document_centre_420 document_centre…
|
Unknown vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to cause a denial of service or rea…
|
NVD-CWE-Other
|
CVE-2005-2646
|
2008-09-6 05:52 |
2005-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357850
|
4.3 |
MEDIUM
|
xerox
|
document_centre_265 document_centre_332 document_centre_340 document_centre_420 document_centre_490 document_centre_535 document_centre_555
|
Cross-site scripting (XSS) vulnerability in Xerox MicroServer Web Server in Document Centre 220 through 265, 332 and 340, 420 through 490, and 535 through 555 allows remote attackers to inject arbitr…
|
NVD-CWE-Other
|
CVE-2005-2647
|
2008-09-6 05:52 |
2005-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|