|
312301
|
5.0 |
MEDIUM
|
steve_kneizys
|
agora.cgi
|
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an err…
|
NVD-CWE-Other
|
CVE-2002-0215
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312302
|
5.0 |
MEDIUM
|
xoops
|
xoops
|
userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter.
|
NVD-CWE-Other
|
CVE-2002-0216
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312303
|
7.5 |
HIGH
|
xoops
|
xoops
|
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Messa…
|
NVD-CWE-Other
|
CVE-2002-0217
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312304
|
7.2 |
HIGH
|
sas
|
sas_base sas_integration_technologies
|
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a …
|
NVD-CWE-Other
|
CVE-2002-0218
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312305
|
7.2 |
HIGH
|
sas
|
sas_base sas_integration_technologies
|
Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.
|
NVD-CWE-Other
|
CVE-2002-0219
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312306
|
7.5 |
HIGH
|
phpsmssend
|
phpsmssend
|
phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters.
|
NVD-CWE-Other
|
CVE-2002-0220
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312307
|
5.0 |
MEDIUM
|
etype
|
eserv
|
Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from ac…
|
NVD-CWE-Other
|
CVE-2002-0221
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312308
|
7.5 |
HIGH
|
etype
|
eserv
|
Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.
|
NVD-CWE-Other
|
CVE-2002-0222
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312309
|
7.5 |
HIGH
|
infopop wired_community_software
|
ultimate_bulletin_board wwwthreads
|
Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends i…
|
NVD-CWE-Other
|
CVE-2002-0223
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312310
|
5.0 |
MEDIUM
|
microsoft
|
msn_messenger
|
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more wh…
|
NVD-CWE-Other
|
CVE-2002-0228
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312311
|
7.2 |
HIGH
|
caldera
|
unixware
|
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privileges by modifying the LC_MESSAGE environment variable to read other message cat…
|
NVD-CWE-Other
|
CVE-2002-0246
|
2008-09-11 09:00 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312312
|
7.2 |
HIGH
|
wliang
|
wmtv
|
Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0247
|
2008-09-11 09:00 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312313
|
7.2 |
HIGH
|
wliang
|
wmtv
|
wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file.
|
NVD-CWE-Other
|
CVE-2002-0248
|
2008-09-11 09:00 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312314
|
10.0 |
HIGH
|
caldera
|
unixware openunix
|
Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi…
|
NVD-CWE-Other
|
CVE-2002-0311
|
2008-09-11 09:00 |
2002-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312315
|
7.5 |
HIGH
|
xerox
|
workcentre_232 workcentre_238 workcentre_245 workcentre_255 workcentre_265 workcentre_275
|
Unspecified vulnerability in the Web User Interface in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to by…
|
NVD-CWE-Other
|
CVE-2006-6434
|
2008-09-11 05:39 |
2006-12-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312316
|
7.5 |
HIGH
|
xerox
|
workcentre
|
The SNMP implementation in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 does not generate authentication failure traps, which all…
|
NVD-CWE-Other
|
CVE-2006-6435
|
2008-09-11 05:39 |
2006-12-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312317
|
6.8 |
MEDIUM
|
xerox
|
workcentre_232 workcentre_238 workcentre_245 workcentre_255 workcentre_265 workcentre_275
|
Cross-site scripting (XSS) vulnerability in the Network controller in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote …
|
NVD-CWE-Other
|
CVE-2006-6436
|
2008-09-11 05:39 |
2006-12-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312318
|
7.8 |
HIGH
|
xerox
|
workcentre
|
ops3-dmn in Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows attackers to cause a denial of service (application crash and cor…
|
NVD-CWE-Other
|
CVE-2006-6437
|
2008-09-11 05:39 |
2006-12-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312319
|
4.9 |
MEDIUM
|
xerox
|
workcentre_232 workcentre_238 workcentre_245 workcentre_255 workcentre_265 workcentre_275
|
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 leaves sensitive user data in http.log after an Immediate Image Overwrite (IIO), whi…
|
NVD-CWE-Other
|
CVE-2006-6438
|
2008-09-11 05:39 |
2006-12-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312320
|
7.8 |
HIGH
|
xerox
|
workcentre_232 workcentre_238 workcentre_245 workcentre_255 workcentre_265 workcentre_275
|
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows remote attackers to download the audit log and obtain potentially sensitive i…
|
NVD-CWE-Other
|
CVE-2006-6439
|
2008-09-11 05:39 |
2006-12-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312321
|
4.6 |
MEDIUM
|
xerox
|
workcentre_232 workcentre_238 workcentre_245 workcentre_255 workcentre_265 workcentre_275
|
Xerox WorkCentre and WorkCentre Pro before 12.050.03.000, 13.x before 13.050.03.000, and 14.x before 14.050.03.000 allows local users to bypass security controls and boot Alchemy via certain alternat…
|
NVD-CWE-Other
|
CVE-2006-6441
|
2008-09-11 05:39 |
2006-12-10 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312322
|
7.1 |
HIGH
|
madwifi
|
madwifi
|
The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a con…
|
NVD-CWE-Other
|
CVE-2005-4835
|
2008-09-11 04:54 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312323
|
10.0 |
HIGH
|
spey
|
spey
|
Unspecified vulnerability in Spey 0.3.3 has unknown impact and attack vectors related to "A number of security holes which could lead to compromise," a different issue than CVE-2005-4846.
|
NVD-CWE-noinfo
|
CVE-2005-4847
|
2008-09-11 04:54 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312324
|
4.3 |
MEDIUM
|
ocomon
|
ocomon
|
Cross-site scripting (XSS) vulnerability in OcoMon 1.20, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-4663
|
2008-09-11 04:53 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312325
|
7.5 |
HIGH
|
rarlab
|
winrar
|
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when Wi…
|
NVD-CWE-Other
|
CVE-2005-3262
|
2008-09-11 04:46 |
2005-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312326
|
7.5 |
HIGH
|
rarlab
|
winrar
|
Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name.
|
NVD-CWE-Other
|
CVE-2005-3263
|
2008-09-11 04:46 |
2005-10-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312327
|
7.5 |
HIGH
|
accelerated_enterprise_solutions
|
accelerated_mortgage_manager
|
SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands via the password field.
|
NVD-CWE-Other
|
CVE-2005-3290
|
2008-09-11 04:46 |
2005-10-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312328
|
5.0 |
MEDIUM
|
squid suse
|
squid suse_linux
|
Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).
|
NVD-CWE-Other
|
CVE-2005-3322
|
2008-09-11 04:46 |
2005-10-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312329
|
7.2 |
HIGH
|
sco
|
unixware
|
Stack-based buffer overflow in ppp in SCO Unixware 7.1.3 and 7.1.4, and possibly earlier versions, allows local users to execute arbitrary code via a long argument to the (1) prompt or (2) defprompt …
|
NVD-CWE-Other
|
CVE-2005-2927
|
2008-09-11 04:44 |
2005-10-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312330
|
6.8 |
MEDIUM
|
ibm
|
rational_clearquest
|
Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (X…
|
NVD-CWE-Other
|
CVE-2005-2994
|
2008-09-11 04:44 |
2005-09-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312331
|
5.1 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execute arbitrary code via a crafted Microsoft Word file.
|
NVD-CWE-Other
|
CVE-2005-2502
|
2008-09-11 04:42 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312332
|
4.6 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.
|
NVD-CWE-Other
|
CVE-2005-2503
|
2008-09-11 04:42 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312333
|
10.0 |
HIGH
|
jed_wing
|
chm_lib
|
Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2005-2659
|
2008-09-11 04:42 |
2005-11-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312334
|
2.1 |
LOW
|
netbsd
|
netbsd
|
The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block …
|
NVD-CWE-Other
|
CVE-2005-2134
|
2008-09-11 04:41 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312335
|
7.5 |
HIGH
|
easyphpcalendar
|
easyphpcalendar
|
PHP remote file inclusion vulnerability in EasyPHPCalendar 6.1.5 and earlier allows remote attackers to execute arbitrary code via the serverPath parameter.
|
NVD-CWE-Other
|
CVE-2005-2155
|
2008-09-11 04:41 |
2005-07-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312336
|
7.5 |
HIGH
|
mms_ripper
|
mms_ripper
|
Buffer overflow in the mms_interp_header function in mms.c in MMS Ripper before 0.6.4 might allow remote attackers to execute arbitrary code via a file with more than 20 streams.
|
NVD-CWE-Other
|
CVE-2005-2213
|
2008-09-11 04:41 |
2005-07-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312337
|
4.3 |
MEDIUM
|
seo-board
|
seo-board
|
Cross-site scripting (XSS) vulnerability in smilies_popup.php in SEO-Board 1.0 allows remote attackers to inject arbitrary web script or HTML via the doc parameter.
|
NVD-CWE-Other
|
CVE-2005-2333
|
2008-09-11 04:41 |
2005-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312338
|
7.5 |
HIGH
|
electricmonk
|
proms
|
Multiple unknown vulnerabilities in PROMS 0.11 allow "non-authorized users" to (1) view or modify the project member list or (2) modify the todos list.
|
NVD-CWE-Other
|
CVE-2005-1737
|
2008-09-11 04:40 |
2005-05-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312339
|
5.0 |
MEDIUM
|
w.m.r._simpson
|
bookreview
|
BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect …
|
NVD-CWE-Other
|
CVE-2005-1783
|
2008-09-11 04:40 |
2005-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312340
|
2.6 |
LOW
|
microsoft
|
windows_98se
|
User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and …
|
NVD-CWE-Other
|
CVE-2005-1793
|
2008-09-11 04:40 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312341
|
4.3 |
MEDIUM
|
clam_anti-virus
|
clamav
|
Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to ind…
|
NVD-CWE-Other
|
CVE-2005-1800
|
2008-09-11 04:40 |
2005-05-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312342
|
2.6 |
LOW
|
nokia
|
9500
|
The vCard viewer in Nokia 9500 allows attackers to cause a denial of service (crash) via a vCard with a long Name field, which causes the crash when the user views it.
|
NVD-CWE-Other
|
CVE-2005-1801
|
2008-09-11 04:40 |
2005-05-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312343
|
7.5 |
HIGH
|
crob
|
crob_ftp
|
Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary code via (1) an FTP command with a large string followed by the RMD command wit…
|
NVD-CWE-Other
|
CVE-2005-1873
|
2008-09-11 04:40 |
2005-06-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312344
|
3.6 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.
|
NVD-CWE-Other
|
CVE-2005-1430
|
2008-09-11 04:39 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312345
|
5.1 |
MEDIUM
|
ht_editor
|
ht_editor
|
Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow.
|
NVD-CWE-Other
|
CVE-2005-1545
|
2008-09-11 04:39 |
2005-05-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312346
|
5.1 |
MEDIUM
|
ht_editor
|
ht_editor
|
Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.
|
NVD-CWE-Other
|
CVE-2005-1546
|
2008-09-11 04:39 |
2005-05-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312347
|
7.5 |
HIGH
|
opentools
|
attachment_mod
|
Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors.
|
NVD-CWE-Other
|
CVE-2005-1630
|
2008-09-11 04:39 |
2005-05-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312348
|
4.3 |
MEDIUM
|
horde
|
accounts
|
Cross-site scripting (XSS) vulnerability in Horde Accounts module before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1316
|
2008-09-11 04:38 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312349
|
7.5 |
HIGH
|
apache
|
http_server
|
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgi…
|
NVD-CWE-Other
|
CVE-2005-1344
|
2008-09-11 04:38 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312350
|
5.1 |
MEDIUM
|
sylpheed
|
sylpheed
|
Buffer overflow in Sylpheed before 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attachments with MIME-encoded file names.
|
NVD-CWE-Other
|
CVE-2005-0926
|
2008-09-11 04:37 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|