|
313251
|
4.6 |
MEDIUM
|
microsoft
|
outlook_connector
|
Microsoft Outlook 2002 Connector for IBM Lotus Domino 2.0 allows local users to save passwords and login credentials locally, even when password caching is disabled by a group policy.
|
NVD-CWE-Other
|
CVE-2005-0921
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313252
|
5.0 |
MEDIUM
|
symantec
|
norton_antivirus norton_internet_security norton_system_works
|
Unknown vulnerability in the Auto-Protect module in Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denial…
|
NVD-CWE-Other
|
CVE-2005-0922
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313253
|
2.1 |
LOW
|
symantec
|
norton_antivirus norton_internet_security norton_system_works
|
The SmartScan feature in the Auto-Protect module for Symantec Norton AntiVirus 2004 and 2005, as also used in Internet Security 2004/2005 and System Works 2004/2005, allows attackers to cause a denia…
|
NVD-CWE-Other
|
CVE-2005-0923
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313254
|
10.0 |
HIGH
|
web-app.org
|
webapp
|
Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences.
|
NVD-CWE-Other
|
CVE-2005-0927
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313255
|
4.3 |
MEDIUM
|
chatness
|
chatness
|
Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message paramete…
|
NVD-CWE-Other
|
CVE-2005-0930
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313256
|
7.5 |
HIGH
|
jimmy
|
the_includer
|
PHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code.
|
NVD-CWE-Other
|
CVE-2005-0931
|
2008-09-6 05:47 |
2005-03-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313257
|
4.3 |
MEDIUM
|
wackowiki
|
wackowiki
|
Multiple cross-site scripting (XSS) vulnerabilities in WackoWiki R4 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-0934
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313258
|
7.5 |
HIGH
|
yepyep
|
mtftpd
|
Buffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path.
|
NVD-CWE-Other
|
CVE-2005-0959
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313259
|
5.0 |
MEDIUM
|
openbsd
|
openbsd
|
Multiple vulnerabilities in the SACK functionality in (1) tcp_input.c and (2) tcp_usrreq.c OpenBSD 3.5 and 3.6 allow remote attackers to cause a denial of service (memory exhaustion or system crash).
|
NVD-CWE-Other
|
CVE-2005-0960
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313260
|
4.3 |
MEDIUM
|
horde
|
application_framework
|
Cross-site scripting (XSS) vulnerability in Horde 3.0.4 before 3.0.4-RC2 allows remote attackers to inject arbitrary web script or HTML via the parent frame title.
|
NVD-CWE-Other
|
CVE-2005-0961
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313261
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via craf…
|
NVD-CWE-Other
|
CVE-2005-0969
|
2008-09-6 05:47 |
2005-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313262
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
|
NVD-CWE-Other
|
CVE-2005-0971
|
2008-09-6 05:47 |
2005-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313263
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
|
NVD-CWE-Other
|
CVE-2005-0972
|
2008-09-6 05:47 |
2005-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313264
|
2.1 |
LOW
|
apple
|
mac_os_x
|
Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.
|
NVD-CWE-Other
|
CVE-2005-0973
|
2008-09-6 05:47 |
2005-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313265
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
|
NVD-CWE-Other
|
CVE-2005-0974
|
2008-09-6 05:47 |
2005-05-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313266
|
5.0 |
MEDIUM
|
apple hmdt omnigroup
|
safari shiira omniweb
|
AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest Javascript componen…
|
NVD-CWE-Other
|
CVE-2005-0976
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313267
|
2.1 |
LOW
|
-
|
-
|
Unspecified vulnerability in the Mac OS X kernel before 10.3.8 allows local users to cause a denial of service (temporary hang) via unspecified attack vectors related to the fan control unit (FCU) dr…
|
NVD-CWE-Other
|
CVE-2005-0985
|
2008-09-6 05:47 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313268
|
5.0 |
MEDIUM
|
irc_services
|
nickserv_listlinks
|
Unknown vulnerability in IRC Services NickServ LISTLINKS before 5.0.50 allows remote attackers to obtain the links of a nick.
|
NVD-CWE-Other
|
CVE-2005-0987
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313269
|
2.1 |
LOW
|
-
|
-
|
RC.BOOT in IBM AIX 5.1, 5.2, and 5.3 does not "use a secure location for temporary files," which allows local users to have an unknown impact, probably by overwriting files.
|
NVD-CWE-Other
|
CVE-2005-0991
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313270
|
4.3 |
MEDIUM
|
early_impact
|
productcart
|
Multiple cross-site scripting (XSS) vulnerabilities in ProductCart 2.7 allow remote attackers to inject arbitrary web script or HTML via (1) the keyword parameter to advSearch_h.asp, (2) the redirect…
|
NVD-CWE-Other
|
CVE-2005-0995
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313271
|
4.3 |
MEDIUM
|
asp-dev
|
xm_forum
|
Cross-site scripting (XSS) vulnerability in posts.asp for ASP-DEv XM Forum RC3 allows remote attackers to inject arbitrary web script or HTML via a "javascript:" URL in an IMG tag.
|
NVD-CWE-Other
|
CVE-2005-1008
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313272
|
7.5 |
HIGH
|
iatek
|
siteenable
|
SQL injection vulnerability in content.asp in SiteEnable allows remote attackers to execute arbitrary SQL commands via the sortby parameter.
|
NVD-CWE-Other
|
CVE-2005-1011
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313273
|
10.0 |
HIGH
|
mailenable
|
imapd
|
Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
|
NVD-CWE-Other
|
CVE-2005-1015
|
2008-09-6 05:47 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313274
|
7.5 |
HIGH
|
f-secure
|
f-secure_anti-virus f-secure_internet_security f-secure_personal_express internet_gatekeeper
|
Heap-based buffer overflow in multiple F-Secure Anti-Virus and Internet Security products allows remote attackers to execute arbitrary code via a crafted ARJ archive.
|
NVD-CWE-Other
|
CVE-2005-0350
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313275
|
4.6 |
MEDIUM
|
sco
|
openserver
|
Buffer overflow in (1) termsh, (2) atcronsh, and (3) auditsh in SCO OpenServer 5.0.6 and 5.0.7 might allow local users to execute arbitrary code via a long HOME environment variable.
|
CWE-119
バッファエラー
|
CVE-2005-0351
|
2008-09-6 05:46 |
2005-04-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313276
|
5.0 |
MEDIUM
|
microsoft
|
log_sink_class_activex_control
|
The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0360
|
2008-09-6 05:46 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313277
|
4.6 |
MEDIUM
|
awstats
|
awstats
|
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.
|
NVD-CWE-Other
|
CVE-2005-0362
|
2008-09-6 05:46 |
2005-02-9 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313278
|
7.5 |
HIGH
|
awstats
|
awstats
|
awstats.pl in AWStats 4.0 and 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.
|
NVD-CWE-Other
|
CVE-2005-0363
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313279
|
4.3 |
MEDIUM
|
mailreader.com
|
mailreader.com
|
Cross-site scripting (XSS) vulnerability in network.cgi in mailreader before 2.3.29 earlier allows remote attackers to inject arbitrary web script or HTML via MIME text/enriched or text/richtext mess…
|
NVD-CWE-Other
|
CVE-2005-0386
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313280
|
2.1 |
LOW
|
remstats
|
remstats
|
remstats 1.0.13 and earlier, when processing uptime data, allows local users to create or overwrite arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-0387
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313281
|
7.5 |
HIGH
|
remstats
|
remstats
|
Unknown vulnerability in the remoteping service in remstats 1.0.13 and earlier allows remote attackers to execute arbitrary commands "due to missing input sanitising."
|
NVD-CWE-Other
|
CVE-2005-0388
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313282
|
7.2 |
HIGH
|
crip
|
crip
|
The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-0393
|
2008-09-6 05:46 |
2005-07-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313283
|
5.0 |
MEDIUM
|
kmail kde
|
kmail kde
|
KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
|
NVD-CWE-Other
|
CVE-2005-0404
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313284
|
7.5 |
HIGH
|
sun
|
j2se
|
Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP fil…
|
NVD-CWE-Other
|
CVE-2005-0418
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313285
|
5.0 |
MEDIUM
|
ibm
|
websphere_application_server
|
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL t…
|
NVD-CWE-Other
|
CVE-2005-0425
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313286
|
5.0 |
MEDIUM
|
bea
|
weblogic_server
|
BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier fo…
|
NVD-CWE-Other
|
CVE-2005-0432
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313287
|
7.5 |
HIGH
|
awstats
|
awstats
|
Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.
|
NVD-CWE-Other
|
CVE-2005-0437
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313288
|
4.6 |
MEDIUM
|
vmware
|
workstation
|
VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0444
|
2008-09-6 05:46 |
2005-02-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313289
|
5.0 |
MEDIUM
|
sami
|
sami_http_server
|
Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.
|
NVD-CWE-Other
|
CVE-2005-0450
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313290
|
5.0 |
MEDIUM
|
sami
|
sami_http_server
|
Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.
|
NVD-CWE-Other
|
CVE-2005-0451
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313291
|
5.0 |
MEDIUM
|
lighttpd
|
lighttpd
|
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL …
|
NVD-CWE-Other
|
CVE-2005-0453
|
2008-09-6 05:46 |
2005-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313292
|
5.0 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP er…
|
NVD-CWE-Other
|
CVE-2005-0459
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313293
|
5.0 |
MEDIUM
|
mercuryboard
|
mercuryboard
|
index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.
|
NVD-CWE-Other
|
CVE-2005-0460
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313294
|
5.0 |
MEDIUM
|
-
|
-
|
Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."
|
NVD-CWE-Other
|
CVE-2005-0461
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313295
|
4.3 |
MEDIUM
|
mercuryboard
|
mercuryboard
|
Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.
|
NVD-CWE-Other
|
CVE-2005-0462
|
2008-09-6 05:46 |
2005-02-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313296
|
7.5 |
HIGH
|
inl
|
ulog-php
|
Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port…
|
NVD-CWE-Other
|
CVE-2005-0463
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313297
|
2.1 |
LOW
|
sgi
|
irix
|
gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary file…
|
NVD-CWE-Other
|
CVE-2005-0464
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313298
|
2.1 |
LOW
|
sgi
|
irix
|
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.
|
NVD-CWE-Other
|
CVE-2005-0465
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313299
|
7.5 |
HIGH
|
gproftpd
|
gproftpd
|
Format string vulnerability in gprostats for GProFTPD before 8.1.9 may allow remote attackers to execute arbitrary code via an FTP transfer with a crafted filename that causes format string specifier…
|
NVD-CWE-Other
|
CVE-2005-0484
|
2008-09-6 05:46 |
2005-03-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313300
|
4.9 |
MEDIUM
|
linux
|
linux_kernel
|
The /proc handling (proc/base.c) Linux kernel 2.4 before 2.4.17 allows local users to cause a denial of service via unknown vectors that cause an invalid access of free memory.
|
NVD-CWE-Other
|
CVE-2005-0489
|
2008-09-6 05:46 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|