|
358001
|
7.5 |
HIGH
|
cisco
|
ipvc-3510-mcu ipvc-3520-gw-2b ipvc-3520-gw-2b2v ipvc-3520-gw-2v ipvc-3520-gw-4v ipvc-3525-gw-1p ipvc-3530-vta
|
Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify c…
|
NVD-CWE-Other
|
CVE-2005-0612
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358002
|
5.0 |
MEDIUM
|
fckeditor
|
fckeditor
|
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0613
|
2008-09-6 05:46 |
2005-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358003
|
6.4 |
MEDIUM
|
nexland symantec
|
pro800turbo firewall_vpn_appliance_200r gateway_security_360 gateway_security_460
|
The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, w…
|
NVD-CWE-Other
|
CVE-2005-0618
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358004
|
2.1 |
LOW
|
bfriendly.com
|
einstein
|
Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local users to steal the information.
|
NVD-CWE-Other
|
CVE-2005-0620
|
2008-09-6 05:46 |
2005-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358005
|
4.6 |
MEDIUM
|
trolltech
|
qt
|
Qt before 3.3.4 searches the BUILD_PREFIX directory, which could be world-writable, to load shared libraries regardless of the LD_LIBRARY_PATH environment variable, which allows local users to execut…
|
NVD-CWE-Other
|
CVE-2005-0627
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358006
|
10.0 |
HIGH
|
foxmail
|
foxmail_email_server
|
Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.
|
NVD-CWE-Other
|
CVE-2005-0635
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358007
|
10.0 |
HIGH
|
foxmail
|
foxmail_email_server
|
Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.
|
NVD-CWE-Other
|
CVE-2005-0636
|
2008-09-6 05:46 |
2005-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358008
|
7.5 |
HIGH
|
xli altlinux suse
|
xli alt_linux suse_linux
|
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer …
|
NVD-CWE-Other
|
CVE-2005-0639
|
2008-09-6 05:46 |
2005-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358009
|
7.5 |
HIGH
|
mcafee
|
antivirus_engine
|
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file with a type 2 header file name field, a variant of C…
|
NVD-CWE-Other
|
CVE-2005-0644
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358010
|
4.3 |
MEDIUM
|
pixel-apes_group
|
safehtml
|
Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."
|
NVD-CWE-Other
|
CVE-2005-0648
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358011
|
4.3 |
MEDIUM
|
pixel-apes_group
|
safehtml
|
Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via "hexadecimal HTML entities."
|
NVD-CWE-Other
|
CVE-2005-0649
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358012
|
4.6 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended.
|
NVD-CWE-Other
|
CVE-2005-0653
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358013
|
4.3 |
MEDIUM
|
adalis
|
d-forum
|
Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.…
|
NVD-CWE-Other
|
CVE-2005-0660
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358014
|
7.5 |
HIGH
|
woltlab
|
burning_board
|
SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or…
|
NVD-CWE-Other
|
CVE-2005-0661
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358015
|
4.3 |
MEDIUM
|
mercuryboard
|
mercuryboard
|
Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.
|
NVD-CWE-Other
|
CVE-2005-0662
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358016
|
5.1 |
MEDIUM
|
john_bradley
|
xv
|
Format string vulnerability in xv before 3.10a allows remote attackers to execute arbitrary code via format string specifiers in a filename.
|
NVD-CWE-Other
|
CVE-2005-0665
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358017
|
4.6 |
MEDIUM
|
the_pax_team
|
pax_linux
|
Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass in…
|
NVD-CWE-Other
|
CVE-2005-0666
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358018
|
5.1 |
MEDIUM
|
sylpheed sylpheed-claws altlinux gentoo redhat
|
sylpheed sylpheed-claws alt_linux linux enterprise_linux fedora_core linux_advanced_workstation
|
Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters t…
|
NVD-CWE-Other
|
CVE-2005-0667
|
2008-09-6 05:46 |
2005-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358019
|
7.5 |
HIGH
|
christian_hilgers
|
http_anti_virus_proxy_\(havp\)
|
Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files.
|
NVD-CWE-Other
|
CVE-2005-0668
|
2008-09-6 05:46 |
2005-03-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358020
|
7.5 |
HIGH
|
ca3de
|
ca3de
|
Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a command.
|
NVD-CWE-Other
|
CVE-2005-0671
|
2008-09-6 05:46 |
2005-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358021
|
7.5 |
HIGH
|
ca3de
|
ca3de
|
Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via text strings that are not null terminated, which triggers a null dereference.
|
NVD-CWE-Other
|
CVE-2005-0672
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358022
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in usercp_register.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) a…
|
NVD-CWE-Other
|
CVE-2005-0673
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358023
|
4.3 |
MEDIUM
|
phpoutsourcing
|
zorum
|
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.5 allows remote attackers to inject arbitrary web script or HTML via the (1) list or (2) frommethod parameters.
|
NVD-CWE-Other
|
CVE-2005-0675
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358024
|
7.5 |
HIGH
|
phpoutsourcing
|
zorum
|
index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.
|
NVD-CWE-Other
|
CVE-2005-0676
|
2008-09-6 05:46 |
2005-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358025
|
5.0 |
MEDIUM
|
phpoutsourcing
|
zorum
|
index.php for Zorum 3.5 allows remote attackers to perform certain actions as other users by modifying the id parameter.
|
NVD-CWE-Other
|
CVE-2005-0677
|
2008-09-6 05:46 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358026
|
10.0 |
HIGH
|
kde
|
kde
|
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remo…
|
NVD-CWE-Other
|
CVE-2005-0011
|
2008-09-6 05:45 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358027
|
2.1 |
LOW
|
-
|
-
|
The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-0017
|
2008-09-6 05:45 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358028
|
2.1 |
LOW
|
f2c_open_source_project
|
f2c_translator
|
The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-0018
|
2008-09-6 05:45 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358029
|
5.0 |
MEDIUM
|
delegate etl
|
delegate
|
The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could t…
|
NVD-CWE-Other
|
CVE-2005-0036
|
2008-09-6 05:45 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358030
|
5.0 |
MEDIUM
|
dnrd
|
dnrd
|
The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an i…
|
NVD-CWE-Other
|
CVE-2005-0037
|
2008-09-6 05:45 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358031
|
5.0 |
MEDIUM
|
dnrd
|
dnrd
|
This vulnerability is addressed in the following product release:
dnrd, dnrd, 2.10
|
NVD-CWE-Other
|
CVE-2005-0037
|
2008-09-6 05:45 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358032
|
5.0 |
MEDIUM
|
powerdns
|
powerdns
|
The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could t…
|
NVD-CWE-Other
|
CVE-2005-0038
|
2008-09-6 05:45 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358033
|
7.2 |
HIGH
|
synaesthesia
|
synaesthesia
|
Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbit…
|
NVD-CWE-Other
|
CVE-2005-0070
|
2008-09-6 05:45 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358034
|
10.0 |
HIGH
|
tcp
|
tcp
|
The original design of TCP does not check that the TCP sequence number in an ICMP error message is within the range of sequence numbers for data that has been sent but not acknowledged (aka "TCP sequ…
|
NVD-CWE-Other
|
CVE-2005-0065
|
2008-09-6 05:45 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358035
|
5.0 |
MEDIUM
|
tcp
|
tcp
|
The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has alr…
|
NVD-CWE-Other
|
CVE-2005-0066
|
2008-09-6 05:45 |
2004-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358036
|
5.0 |
MEDIUM
|
tcp
|
tcp
|
The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connec…
|
NVD-CWE-Other
|
CVE-2005-0067
|
2008-09-6 05:45 |
2004-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358037
|
5.0 |
MEDIUM
|
tcp
|
tcp
|
The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and c…
|
NVD-CWE-Other
|
CVE-2005-0068
|
2008-09-6 05:45 |
2004-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358038
|
4.6 |
MEDIUM
|
debian
|
sympa
|
Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0073
|
2008-09-6 05:45 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358039
|
7.2 |
HIGH
|
xpcd
|
xpcd
|
Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0074
|
2008-09-6 05:45 |
2005-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358040
|
4.6 |
MEDIUM
|
abuse
|
abuse-sdl
|
Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.
|
NVD-CWE-Other
|
CVE-2005-0098
|
2008-09-6 05:45 |
2005-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358041
|
2.1 |
LOW
|
abuse
|
abuse-sdl
|
The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0099
|
2008-09-6 05:45 |
2005-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358042
|
4.6 |
MEDIUM
|
typespeed
|
typespeed
|
Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0105
|
2008-09-6 05:45 |
2005-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358043
|
7.5 |
HIGH
|
debian
|
bsmtpd
|
bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2005-0107
|
2008-09-6 05:45 |
2005-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358044
|
2.1 |
LOW
|
checkpoint zonelabs
|
check_point_integrity_client zonealarm zonealarm_wireless_security
|
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify tha…
|
NVD-CWE-Other
|
CVE-2005-0114
|
2008-09-6 05:45 |
2005-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358045
|
7.5 |
HIGH
|
awstats
|
awstats
|
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
|
CWE-20
Improper Input Validation
|
CVE-2005-0116
|
2008-09-6 05:45 |
2005-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358046
|
4.6 |
MEDIUM
|
xshisen
|
xshisen
|
Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.
|
NVD-CWE-Other
|
CVE-2005-0117
|
2008-09-6 05:45 |
2005-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358047
|
2.1 |
LOW
|
helvis
|
helvis
|
helvis 1.8h2_1 and earlier stores recovery files in world readable directories with world readable permissions, which allows local users to read the recovered files of other users.
|
NVD-CWE-Other
|
CVE-2005-0118
|
2008-09-6 05:45 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358048
|
2.1 |
LOW
|
helvis
|
helvis
|
helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.
|
NVD-CWE-Other
|
CVE-2005-0119
|
2008-09-6 05:45 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358049
|
2.1 |
LOW
|
-
|
-
|
helvis 1.8h2_1 and earlier allows local users to delete arbitrary files via the elvprsv setuid program.
|
NVD-CWE-Other
|
CVE-2005-0120
|
2008-09-6 05:45 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358050
|
7.5 |
HIGH
|
adobe
|
creative_suite photoshop premiere
|
Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administra…
|
NVD-CWE-Other
|
CVE-2005-0151
|
2008-09-6 05:45 |
2005-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|