|
313151
|
10.0 |
HIGH
|
symantec_veritas
|
i3_focalpoint_server
|
Unknown vulnerability in Veritas i3 Focalpoint Server 7.1 and earlier has unknown attack vectors and unknown but "critical" impact.
|
NVD-CWE-Other
|
CVE-2005-1131
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313152
|
5.0 |
MEDIUM
|
kerio
|
kerio_mailserver
|
Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain e-mail messages.
|
NVD-CWE-Other
|
CVE-2005-1138
|
2008-09-6 05:48 |
2005-04-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313153
|
4.3 |
MEDIUM
|
mywebland
|
mybloggie
|
Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.
|
NVD-CWE-Other
|
CVE-2005-1140
|
2008-09-6 05:48 |
2005-04-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313154
|
4.3 |
MEDIUM
|
easyphpcalendar
|
easyphpcalendar
|
Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.
|
NVD-CWE-Other
|
CVE-2005-1143
|
2008-09-6 05:48 |
2005-04-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313155
|
5.0 |
MEDIUM
|
easyphpcalendar
|
easyphpcalendar
|
popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.
|
NVD-CWE-Other
|
CVE-2005-1144
|
2008-09-6 05:48 |
2005-04-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313156
|
5.0 |
MEDIUM
|
easyphpcalendar
|
easyphpcalendar
|
Version 6.2.8 and above are fixed.
|
NVD-CWE-Other
|
CVE-2005-1144
|
2008-09-6 05:48 |
2005-04-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313157
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.
|
NVD-CWE-Other
|
CVE-2005-1149
|
2008-09-6 05:48 |
2005-04-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313158
|
5.0 |
MEDIUM
|
sun
|
java_system_web_server
|
Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).
|
NVD-CWE-Other
|
CVE-2005-1150
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313159
|
7.2 |
HIGH
|
debian
|
qpopper
|
qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.
|
NVD-CWE-Other
|
CVE-2005-1151
|
2008-09-6 05:48 |
2005-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313160
|
2.1 |
LOW
|
debian
|
qpopper
|
popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.
|
NVD-CWE-Other
|
CVE-2005-1152
|
2008-09-6 05:48 |
2005-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313161
|
4.3 |
MEDIUM
|
jaws
|
jaws
|
Cross-site scripting (XSS) vulnerability in the NewTerm function in GlossaryModel.php in JAWS 0.4 allows remote attackers to inject arbitrary web script or HTML via the (1) term or (2) description.
|
NVD-CWE-Other
|
CVE-2005-1231
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313162
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb-auction
|
auction_my_auctions.php in phpbb-Auction 1.2m and earlier allows remote attackers to obtain sensitive information via an invalid mode parameter, which leaks the full path in a PHP error message.
|
NVD-CWE-Other
|
CVE-2005-1235
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313163
|
5.0 |
MEDIUM
|
phpbb_group
|
phpbb-auction
|
Fixed updated version on http://www.phpbb-auction.com/
|
NVD-CWE-Other
|
CVE-2005-1235
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313164
|
7.5 |
HIGH
|
duware
|
duportal
|
Multiple SQL injection vulnerabilities in DUware DUportal 3.1.2 and 3.1.2 SQL allow remote attackers to execute arbitrary SQL commands via the (1) iChannel parameter to channel.asp or search.asp, (2)…
|
NVD-CWE-Other
|
CVE-2005-1236
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313165
|
10.0 |
HIGH
|
vladislav_bogdanov
|
snmppd
|
Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format strin…
|
NVD-CWE-Other
|
CVE-2005-1246
|
2008-09-6 05:48 |
2005-04-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313166
|
5.0 |
MEDIUM
|
novell
|
nsure_audit
|
webadmin.exe in Novell Nsure Audit 1.0.1 allows remote attackers to cause a denial of service via malformed ASN.1 packets in corrupt client certificates to an SSL server, as demonstrated using an exp…
|
NVD-CWE-Other
|
CVE-2005-1247
|
2008-09-6 05:48 |
2004-01-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313167
|
7.5 |
HIGH
|
ipswitch
|
whatsup
|
SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allows remote attackers to execute arbitrary SQL commands via the…
|
NVD-CWE-Other
|
CVE-2005-1250
|
2008-09-6 05:48 |
2005-06-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313168
|
10.0 |
HIGH
|
mysql
|
maxdb
|
Stack-based buffer overflow in the getIfHeader function in the WebDAV functionality in MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via an HTTP unlock request and a …
|
NVD-CWE-Other
|
CVE-2005-1274
|
2008-09-6 05:48 |
2005-04-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313169
|
5.0 |
MEDIUM
|
ethereal_group
|
ethereal
|
Ethereal 0.10.10 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.
|
NVD-CWE-Other
|
CVE-2005-1281
|
2008-09-6 05:48 |
2005-04-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313170
|
7.5 |
HIGH
|
inter7
|
sqwebmail
|
SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.
|
NVD-CWE-Other
|
CVE-2005-1308
|
2008-09-6 05:48 |
2005-04-15 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313171
|
4.3 |
MEDIUM
|
eaden_mckee
|
bblog
|
Cross-site scripting (XSS) vulnerability in bBlog 0.7.4 allows remote attackers to inject arbitrary web script or HTML via the (1) entry title field or (2) comment body text.
|
NVD-CWE-Other
|
CVE-2005-1309
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313172
|
7.5 |
HIGH
|
eaden_mckee
|
bblog
|
SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
|
NVD-CWE-Other
|
CVE-2005-1310
|
2008-09-6 05:48 |
2005-04-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313173
|
4.3 |
MEDIUM
|
yappa-ng
|
yappa-ng
|
Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1311
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313174
|
7.5 |
HIGH
|
yappa-ng
|
yappa-ng
|
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1312
|
2008-09-6 05:48 |
2005-04-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313175
|
4.3 |
MEDIUM
|
horde
|
passwd
|
Cross-site scripting (XSS) vulnerability in Horde Passwd module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1313
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313176
|
4.3 |
MEDIUM
|
horde
|
kronolith
|
Cross-site scripting (XSS) vulnerability in Horde Kronolith module before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1314
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313177
|
4.3 |
MEDIUM
|
horde
|
turba
|
Cross-site scripting (XSS) vulnerability in Horde Turba module before 1.2.5 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1315
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313178
|
6.8 |
MEDIUM
|
horde
|
chora
|
Cross-site scripting (XSS) vulnerability in Horde Chora module before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1317
|
2008-09-6 05:48 |
2005-04-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313179
|
4.3 |
MEDIUM
|
horde
|
forwards
|
Cross-site scripting (XSS) vulnerability in Horde Forwards E-Mail Forwarding Manager before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1318
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313180
|
4.3 |
MEDIUM
|
horde
|
imp
|
Cross-site scripting (XSS) vulnerability in Horde IMP Webmail client before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1319
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313181
|
4.3 |
MEDIUM
|
horde
|
mnemo
|
Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1320
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313182
|
4.3 |
MEDIUM
|
horde
|
vaction
|
Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1321
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313183
|
4.3 |
MEDIUM
|
horde
|
nag
|
Cross-site scripting (XSS) vulnerability in Horde Nag Task List Manager before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the parent's frame page title.
|
NVD-CWE-Other
|
CVE-2005-1322
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313184
|
5.0 |
MEDIUM
|
voodoo_circle
|
voodoo_circle
|
Buffer overflow in VooDoo cIRCle BOTNET before 1.0.33 allows remote authenticated attackers to cause a denial of service (client crash) via a crafted packet.
|
NVD-CWE-Other
|
CVE-2005-1326
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313185
|
4.3 |
MEDIUM
|
woltlab
|
burning_board
|
Cross-site scripting (XSS) vulnerability in pms.php for Woltlab Burning Board 2.3.1 PL2 and earlier allows remote attackers to inject arbitrary web script or HTML via the folderid parameter.
|
NVD-CWE-Other
|
CVE-2005-1327
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313186
|
4.9 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled…
|
CWE-20
不適切な入力確認
|
CVE-2005-1330
|
2008-09-6 05:48 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313187
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to …
|
NVD-CWE-Other
|
CVE-2005-1332
|
2008-09-6 05:48 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313188
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Directory traversal vulnerability in the Bluetooth file and object exchange (OBEX) services in Mac OS X 10.3.9 allows remote attackers to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-1333
|
2008-09-6 05:48 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313189
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
|
NVD-CWE-Other
|
CVE-2005-1335
|
2008-09-6 05:48 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313190
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Buffer overflow in the Foundation framework for Mac OS X 10.3.9 allows local users to execute arbitrary code via a long environment variable.
|
NVD-CWE-Other
|
CVE-2005-1336
|
2008-09-6 05:48 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313191
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
|
NVD-CWE-Other
|
CVE-2005-1337
|
2008-09-6 05:48 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313192
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Mac OS X 10.3.9, when using an LDAP server that does not use ldap_extended_operation, may store initial LDAP passwords for new accounts in plaintext.
|
NVD-CWE-Other
|
CVE-2005-1338
|
2008-09-6 05:48 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313193
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
|
NVD-CWE-Other
|
CVE-2005-1339
|
2008-09-6 05:48 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313194
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.
|
NVD-CWE-Other
|
CVE-2005-1340
|
2008-09-6 05:48 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313195
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
|
NVD-CWE-Other
|
CVE-2005-1343
|
2008-09-6 05:48 |
2005-05-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313196
|
2.6 |
LOW
|
symantec
|
antivirus_scan_engine mail_security norton_antivirus norton_internet_security norton_system_works symav_filter_domino_nt web_security
|
Multiple Symantec AntiVirus products, including Norton AntiVirus 2005 11.0.0, Web Security Web Security 3.0.1.72, Mail Security for SMTP 4.0.5.66, AntiVirus Scan Engine 4.3.7.27, SAV/Filter for Domin…
|
NVD-CWE-Other
|
CVE-2005-1346
|
2008-09-6 05:48 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313197
|
4.3 |
MEDIUM
|
drupal
|
drupal
|
Cross-site scripting (XSS) vulnerability in common.inc in Drupal before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via certain inputs.
|
NVD-CWE-Other
|
CVE-2005-0682
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313198
|
7.5 |
HIGH
|
mlterm
|
mlterm
|
Integer overflow in mlterm 2.5.0 through 2.9.1, with gdk-pixbuf support enabled, allows remote attackers to execute arbitrary code via a large image file that is used as a background.
|
NVD-CWE-Other
|
CVE-2005-0686
|
2008-09-6 05:47 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313199
|
7.5 |
HIGH
|
hashcash
|
hashcash
|
Format string vulnerability in Hashcash 1.16 allows remote attackers to cause a denial of service (memory consumption) and possibly execute arbitrary code via format string specifiers in a reply addr…
|
NVD-CWE-Other
|
CVE-2005-0687
|
2008-09-6 05:47 |
2005-03-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313200
|
7.5 |
HIGH
|
jowood_productions
|
chaser
|
Buffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and execute arbitrary code via a long nickname.
|
NVD-CWE-Other
|
CVE-2005-0693
|
2008-09-6 05:47 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|