265811
|
- |
|
s9y
|
serendipity
|
Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin…
|
NVD-CWE-Other
|
CVE-2005-3129
|
2017-07-11 10:33 |
2005-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265812
|
- |
|
virtools
|
web_player
|
Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename.
|
NVD-CWE-Other
|
CVE-2005-3136
|
2017-07-11 10:33 |
2005-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265813
|
- |
|
gnu
|
cfengine
|
The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.
|
NVD-CWE-Other
|
CVE-2005-3137
|
2017-07-11 10:33 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265814
|
- |
|
mozilla
|
bugzilla
|
Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is access…
|
NVD-CWE-Other
|
CVE-2005-3138
|
2017-07-11 10:33 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265815
|
- |
|
mozilla
|
bugzilla
|
Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroup…
|
NVD-CWE-Other
|
CVE-2005-3139
|
2017-07-11 10:33 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265816
|
- |
|
kaspersky_lab
|
kaspersky_anti-virus kaspersky_anti-virus_personal kaspersky_anti-virus_personal_pro kaspersky_personal_security_suite
|
Heap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary code via a CAB file with large records after the hea…
|
NVD-CWE-Other
|
CVE-2005-3142
|
2017-07-11 10:33 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265817
|
- |
|
devellion
|
cubecart
|
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web script or HTML via the redir parameter to (1) cart.php or (2) index.php, or (3) th…
|
NVD-CWE-Other
|
CVE-2005-3152
|
2017-07-11 10:33 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265818
|
- |
|
php_fusion
|
php_fusion
|
Multiple SQL injection vulnerabilities in PHP-Fusion before 6.00.110 allow remote attackers to execute arbitrary SQL commands via (1) the activate parameter in register.php and (2) the cat_id paramet…
|
NVD-CWE-Other
|
CVE-2005-3161
|
2017-07-11 10:33 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265819
|
- |
|
nullsoft
|
winamp
|
Buffer overflow in Nullsoft Winamp 5.094 allows remote attackers to execute arbitrary code via (1) an m3u file containing a long line ending in .wma or (2) a pls file containing a long File1 value en…
|
NVD-CWE-Other
|
CVE-2005-3188
|
2017-07-11 10:33 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
265820
|
- |
|
estsoft
|
alzip
|
Multiple buffer overflows in ALZip 6.12 (Korean), 6.1 (International), and 5.52 (English) allow remote attackers to execute arbitrary code via a long filename in a compressed (1) ALZ, (2) ARJ, (3) ZI…
|
NVD-CWE-Other
|
CVE-2005-3194
|
2017-07-11 10:33 |
2005-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|