|
357951
|
7.5 |
HIGH
|
f-secure
|
f-secure_anti-virus f-secure_internet_security f-secure_personal_express internet_gatekeeper
|
Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.
|
NVD-CWE-Other
|
CVE-2005-0350
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357952
|
4.6 |
MEDIUM
|
sco
|
openserver
|
Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2005-0351
|
2008-09-6 05:46 |
2005-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357953
|
5.0 |
MEDIUM
|
microsoft
|
log_sink_class_activex_control
|
The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0360
|
2008-09-6 05:46 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357954
|
4.6 |
MEDIUM
|
awstats
|
awstats
|
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.
|
NVD-CWE-Other
|
CVE-2005-0362
|
2008-09-6 05:46 |
2005-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357955
|
7.5 |
HIGH
|
awstats
|
awstats
|
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
|
NVD-CWE-Other
|
CVE-2005-0363
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357956
|
4.3 |
MEDIUM
|
mailreader.com
|
mailreader.com
|
Cross-site scripting (XSS) vulnerability in network.cgi in mailreader before 2.3.29 earlier allows remote attackers to inject arbitrary web script or HTML via MIME text/enriched or text/richtext mess…
|
NVD-CWE-Other
|
CVE-2005-0386
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357957
|
2.1 |
LOW
|
remstats
|
remstats
|
remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-0387
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357958
|
7.5 |
HIGH
|
remstats
|
remstats
|
Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."
|
NVD-CWE-Other
|
CVE-2005-0388
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357959
|
7.2 |
HIGH
|
crip
|
crip
|
The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-0393
|
2008-09-6 05:46 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357960
|
5.0 |
MEDIUM
|
kmail kde
|
kmail kde
|
KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
|
NVD-CWE-Other
|
CVE-2005-0404
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357961
|
7.5 |
HIGH
|
sun
|
j2se
|
Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP fil…
|
NVD-CWE-Other
|
CVE-2005-0418
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357962
|
5.0 |
MEDIUM
|
ibm
|
websphere_application_server
|
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL t…
|
NVD-CWE-Other
|
CVE-2005-0425
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357963
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier fo…
|
NVD-CWE-Other
|
CVE-2005-0432
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357964
|
7.5 |
HIGH
|
awstats
|
awstats
|
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
|
NVD-CWE-Other
|
CVE-2005-0437
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357965
|
4.6 |
MEDIUM
|
vmware
|
workstation
|
VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0444
|
2008-09-6 05:46 |
2005-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357966
|
5.0 |
MEDIUM
|
sami
|
sami_http_server
|
Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.
|
NVD-CWE-Other
|
CVE-2005-0450
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357967
|
5.0 |
MEDIUM
|
sami
|
sami_http_server
|
Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.
|
NVD-CWE-Other
|
CVE-2005-0451
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357968
|
5.0 |
MEDIUM
|
lighttpd
|
lighttpd
|
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL …
|
NVD-CWE-Other
|
CVE-2005-0453
|
2008-09-6 05:46 |
2005-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357969
|
5.0 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP er…
|
NVD-CWE-Other
|
CVE-2005-0459
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357970
|
5.0 |
MEDIUM
|
mercuryboard
|
mercuryboard
|
index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.
|
NVD-CWE-Other
|
CVE-2005-0460
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357971
|
5.0 |
MEDIUM
|
-
|
-
|
Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."
|
NVD-CWE-Other
|
CVE-2005-0461
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357972
|
4.3 |
MEDIUM
|
mercuryboard
|
mercuryboard
|
Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.
|
NVD-CWE-Other
|
CVE-2005-0462
|
2008-09-6 05:46 |
2005-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357973
|
7.5 |
HIGH
|
inl
|
ulog-php
|
Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port…
|
NVD-CWE-Other
|
CVE-2005-0463
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357974
|
2.1 |
LOW
|
sgi
|
irix
|
gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary file…
|
NVD-CWE-Other
|
CVE-2005-0464
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357975
|
2.1 |
LOW
|
sgi
|
irix
|
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.
|
NVD-CWE-Other
|
CVE-2005-0465
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357976
|
7.5 |
HIGH
|
gproftpd
|
gproftpd
|
Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifier…
|
NVD-CWE-Other
|
CVE-2005-0484
|
2008-09-6 05:46 |
2005-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357977
|
4.9 |
MEDIUM
|
linux
|
linux_kernel
|
The /proc handling (proc/base.c) Linux kernel 2.4 before 2.4.17 allows local users to cause a denial of service via unknown vectors that cause an invalid access of free memory.
|
NVD-CWE-Other
|
CVE-2005-0489
|
2008-09-6 05:46 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357978
|
4.9 |
MEDIUM
|
linux
|
linux_kernel
|
This vulnerability is addressed in the following product release:
Linux, Linux kernel, 2.4.27
|
NVD-CWE-Other
|
CVE-2005-0489
|
2008-09-6 05:46 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357979
|
2.1 |
LOW
|
fallback-reboot
|
fallback-reboot
|
The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.
|
NVD-CWE-Other
|
CVE-2005-0510
|
2008-09-6 05:46 |
2005-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357980
|
7.5 |
HIGH
|
mambo
|
mambo
|
PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remo…
|
NVD-CWE-Other
|
CVE-2005-0512
|
2008-09-6 05:46 |
2005-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357981
|
4.3 |
MEDIUM
|
verity
|
verity_ultraseek
|
Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.
|
NVD-CWE-Other
|
CVE-2005-0514
|
2008-09-6 05:46 |
2005-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357982
|
2.1 |
LOW
|
webroot_software
|
my_firewall_plus
|
Smc.exe in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before launching the Log Viewer export functionality, which allows local users to corrupt arbitrary f…
|
NVD-CWE-Other
|
CVE-2005-0515
|
2008-09-6 05:46 |
2005-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357983
|
2.1 |
LOW
|
peerftp_5
|
peerftp_5
|
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0517
|
2008-09-6 05:46 |
2005-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357984
|
2.1 |
LOW
|
exeem
|
exeem
|
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.
|
NVD-CWE-Other
|
CVE-2005-0518
|
2008-09-6 05:46 |
2005-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357985
|
2.1 |
LOW
|
-
|
-
|
SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0521
|
2008-09-6 05:46 |
2005-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357986
|
4.6 |
MEDIUM
|
lionmax_software
|
chat_anywhere
|
Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0522
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357987
|
7.5 |
HIGH
|
prozilla
|
prozilla_download_accelerator
|
Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.
|
NVD-CWE-Other
|
CVE-2005-0523
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357988
|
7.5 |
HIGH
|
trend_micro
|
client-server-messaging_suite_smb client-server_suite_smb control_manager interscan_emanager interscan_messaging_security_suite interscan_viruswall interscan_web_security_suite i…
|
Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with…
|
NVD-CWE-Other
|
CVE-2005-0533
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357989
|
5.0 |
MEDIUM
|
ginp
|
ginp
|
Directory traversal vulnerability in (1) GinpPictureServlet.java and (2) PicCollection.java in ginp (Java Photo Gallery Web Application) before 0.22 allows remote attackers to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0538
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357990
|
4.6 |
MEDIUM
|
ibm
|
hardware_management_console
|
Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.
|
NVD-CWE-Other
|
CVE-2005-0539
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357991
|
5.0 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.ph…
|
NVD-CWE-Other
|
CVE-2005-0544
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357992
|
5.0 |
MEDIUM
|
cupidsystems
|
cis_webserver
|
Directory traversal vulnerability in CIS WebServer 3.5.13 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the URL.
|
NVD-CWE-Other
|
CVE-2005-0574
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357993
|
3.6 |
LOW
|
sun
|
solaris
|
Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0576
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357994
|
5.1 |
MEDIUM
|
dna
|
mkbold-mkitalic
|
Format string vulnerability in DNA MKBold-MKItalic 0.06_1 and earlier allows remote attackers to execute arbitrary code via crafted BDF font files.
|
NVD-CWE-Other
|
CVE-2005-0577
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357995
|
4.6 |
MEDIUM
|
freenx
|
freenx
|
nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.
|
NVD-CWE-Other
|
CVE-2005-0579
|
2008-09-6 05:46 |
2005-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357996
|
2.1 |
LOW
|
krzysztof_dabrowski
|
cmd5checkpw
|
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.
|
NVD-CWE-Other
|
CVE-2005-0580
|
2008-09-6 05:46 |
2005-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357997
|
7.2 |
HIGH
|
apple
|
mac_os_x_server
|
Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0594
|
2008-09-6 05:46 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357998
|
2.1 |
LOW
|
php
|
php
|
PHP 4 (PHP4) allows attackers to cause a denial of service (daemon crash) by using the readfile function on a file whose size is a multiple of the page size.
|
NVD-CWE-Other
|
CVE-2005-0596
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357999
|
7.5 |
HIGH
|
webmod
|
webmod
|
Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less …
|
NVD-CWE-Other
|
CVE-2005-0608
|
2008-09-6 05:46 |
2005-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358000
|
7.2 |
HIGH
|
freebsd
|
freebsd
|
Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, …
|
NVD-CWE-Other
|
CVE-2005-0610
|
2008-09-6 05:46 |
2005-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|