|
313301
|
4.9 |
MEDIUM
|
linux
|
linux_kernel
|
This vulnerability is addressed in the following product release:
Linux, Linux kernel, 2.4.27
|
NVD-CWE-Other
|
CVE-2005-0489
|
2008-09-6 05:46 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313302
|
2.1 |
LOW
|
fallback-reboot
|
fallback-reboot
|
The daemon for fallback-reboot before 0.995 allows attackers to cause a denial of service (daemon exit), possibly related to verbose debug messages when the daemon is not on a tty.
|
NVD-CWE-Other
|
CVE-2005-0510
|
2008-09-6 05:46 |
2005-03-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313303
|
7.5 |
HIGH
|
mambo
|
mambo
|
PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remo…
|
NVD-CWE-Other
|
CVE-2005-0512
|
2008-09-6 05:46 |
2005-02-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313304
|
4.3 |
MEDIUM
|
verity
|
verity_ultraseek
|
Cross-site scripting (XSS) vulnerability in Verity Ultraseek before 5.3.3 allows remote attackers to inject arbitrary HTML and web script via search parameters.
|
NVD-CWE-Other
|
CVE-2005-0514
|
2008-09-6 05:46 |
2005-02-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313305
|
2.1 |
LOW
|
webroot_software
|
my_firewall_plus
|
Smc.exe in My Firewall Plus 5.0 build 1117, and possibly other versions, does not drop privileges before launching the Log Viewer export functionality, which allows local users to corrupt arbitrary f…
|
NVD-CWE-Other
|
CVE-2005-0515
|
2008-09-6 05:46 |
2005-05-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313306
|
2.1 |
LOW
|
peerftp_5
|
peerftp_5
|
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0517
|
2008-09-6 05:46 |
2005-02-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313307
|
2.1 |
LOW
|
exeem
|
exeem
|
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain privileges via the proxy_user and proxy_password values.
|
NVD-CWE-Other
|
CVE-2005-0518
|
2008-09-6 05:46 |
2005-02-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313308
|
2.1 |
LOW
|
-
|
-
|
SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0521
|
2008-09-6 05:46 |
2005-02-23 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313309
|
4.6 |
MEDIUM
|
lionmax_software
|
chat_anywhere
|
Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0522
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313310
|
7.5 |
HIGH
|
prozilla
|
prozilla_download_accelerator
|
Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.
|
NVD-CWE-Other
|
CVE-2005-0523
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313311
|
7.5 |
HIGH
|
trend_micro
|
client-server-messaging_suite_smb client-server_suite_smb control_manager interscan_emanager interscan_messaging_security_suite interscan_viruswall interscan_web_security_suite i…
|
Heap-based buffer overflow in Trend Micro AntiVirus Library VSAPI before 7.510, as used in multiple Trend Micro products, allows remote attackers to execute arbitrary code via a crafted ARJ file with…
|
NVD-CWE-Other
|
CVE-2005-0533
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313312
|
5.0 |
MEDIUM
|
ginp
|
ginp
|
Directory traversal vulnerability in (1) GinpPictureServlet.java and (2) PicCollection.java in ginp (Java Photo Gallery Web Application) before 0.22 allows remote attackers to read arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0538
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313313
|
4.6 |
MEDIUM
|
ibm
|
hardware_management_console
|
Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.
|
NVD-CWE-Other
|
CVE-2005-0539
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313314
|
5.0 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 2.6.1 allows remote attackers to obtain the full path of the server via direct requests to (1) sqlvalidator.lib.php, (2) sqlparser.lib.php, (3) select_theme.lib.php, (4) select_lang.lib.ph…
|
NVD-CWE-Other
|
CVE-2005-0544
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313315
|
5.0 |
MEDIUM
|
cupidsystems
|
cis_webserver
|
Directory traversal vulnerability in CIS WebServer 3.5.13 allows remote attackers to read arbitrary files via .. (dot dot) sequences in the URL.
|
NVD-CWE-Other
|
CVE-2005-0574
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313316
|
3.6 |
LOW
|
sun
|
solaris
|
Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0576
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313317
|
5.1 |
MEDIUM
|
dna
|
mkbold-mkitalic
|
Format string vulnerability in DNA MKBold-MKItalic 0.06_1 and earlier allows remote attackers to execute arbitrary code via crafted BDF font files.
|
NVD-CWE-Other
|
CVE-2005-0577
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313318
|
4.6 |
MEDIUM
|
freenx
|
freenx
|
nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.
|
NVD-CWE-Other
|
CVE-2005-0579
|
2008-09-6 05:46 |
2005-02-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313319
|
2.1 |
LOW
|
krzysztof_dabrowski
|
cmd5checkpw
|
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.
|
NVD-CWE-Other
|
CVE-2005-0580
|
2008-09-6 05:46 |
2005-02-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313320
|
7.2 |
HIGH
|
apple
|
mac_os_x_server
|
Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0594
|
2008-09-6 05:46 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313321
|
2.1 |
LOW
|
php
|
php
|
PHP 4 (PHP4) allows attackers to cause a denial of service (daemon crash) by using the readfile function on a file whose size is a multiple of the page size.
|
NVD-CWE-Other
|
CVE-2005-0596
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313322
|
7.5 |
HIGH
|
webmod
|
webmod
|
Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less …
|
NVD-CWE-Other
|
CVE-2005-0608
|
2008-09-6 05:46 |
2005-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313323
|
7.2 |
HIGH
|
freebsd
|
freebsd
|
Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, …
|
NVD-CWE-Other
|
CVE-2005-0610
|
2008-09-6 05:46 |
2005-04-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313324
|
7.5 |
HIGH
|
cisco
|
ipvc-3510-mcu ipvc-3520-gw-2b ipvc-3520-gw-2b2v ipvc-3520-gw-2v ipvc-3520-gw-4v ipvc-3525-gw-1p ipvc-3530-vta
|
Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify c…
|
NVD-CWE-Other
|
CVE-2005-0612
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313325
|
5.0 |
MEDIUM
|
fckeditor
|
fckeditor
|
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0613
|
2008-09-6 05:46 |
2005-02-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313326
|
6.4 |
MEDIUM
|
nexland symantec
|
pro800turbo firewall_vpn_appliance_200r gateway_security_360 gateway_security_460
|
The SMTP binding function in Symantec Firewall/VPN Appliance 200/200R firmware after 1.5Z and before 1.68, Gateway Security 360/360R and 460/460R firmware before vuild 858, and Nexland Pro800turbo, w…
|
NVD-CWE-Other
|
CVE-2005-0618
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313327
|
2.1 |
LOW
|
bfriendly.com
|
einstein
|
Einstein 1.0 stores credit card information in plaintext in the world-readable wallets.dat file, which allows local users to steal the information.
|
NVD-CWE-Other
|
CVE-2005-0620
|
2008-09-6 05:46 |
2005-03-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313328
|
4.6 |
MEDIUM
|
trolltech
|
qt
|
Qt before 3.3.4 searches the BUILD_PREFIX directory, which could be world-writable, to load shared libraries regardless of the LD_LIBRARY_PATH environment variable, which allows local users to execut…
|
NVD-CWE-Other
|
CVE-2005-0627
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313329
|
10.0 |
HIGH
|
foxmail
|
foxmail_email_server
|
Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.
|
NVD-CWE-Other
|
CVE-2005-0635
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313330
|
10.0 |
HIGH
|
foxmail
|
foxmail_email_server
|
Format string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the USER command.
|
NVD-CWE-Other
|
CVE-2005-0636
|
2008-09-6 05:46 |
2005-03-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313331
|
7.5 |
HIGH
|
xli altlinux suse
|
xli alt_linux suse_linux
|
Multiple vulnerabilities in xli before 1.17 may allow remote attackers to execute arbitrary code via "buffer management errors" from certain image properties, some of which may be related to integer …
|
NVD-CWE-Other
|
CVE-2005-0639
|
2008-09-6 05:46 |
2005-03-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313332
|
7.5 |
HIGH
|
mcafee
|
antivirus_engine
|
Buffer overflow in McAfee Scan Engine 4320 with DAT version before 4436 allows remote attackers to execute arbitrary code via a malformed LHA file with a type 2 header file name field, a variant of C…
|
NVD-CWE-Other
|
CVE-2005-0644
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313333
|
4.3 |
MEDIUM
|
pixel-apes_group
|
safehtml
|
Multiple vulnerabilities in Pixel-Apes SafeHTML before 1.3.0 allow remote attackers to bypass cross-site scripting (XSS) protection via (1) "decimal HTML entities" or (2) "the \x00 symbol."
|
NVD-CWE-Other
|
CVE-2005-0648
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313334
|
4.3 |
MEDIUM
|
pixel-apes_group
|
safehtml
|
Pixel-Apes SafeHTML before 1.2.1 allows remote attackers to bypass cross-site scripting (XSS) protection via "hexadecimal HTML entities."
|
NVD-CWE-Other
|
CVE-2005-0649
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313335
|
4.6 |
MEDIUM
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 2.6.1 does not properly grant permissions on tables with an underscore in the name, which grants remote authenticated users more privileges than intended.
|
NVD-CWE-Other
|
CVE-2005-0653
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313336
|
4.3 |
MEDIUM
|
adalis
|
d-forum
|
Multiple cross-site scripting (XSS) vulnerabilities in D-Forum 1.11 allows remote attackers to inject arbitrary web script or HTML via certain fields, as demonstrated using the page parameter in nav.…
|
NVD-CWE-Other
|
CVE-2005-0660
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313337
|
7.5 |
HIGH
|
woltlab
|
burning_board
|
SQL injection vulnerability in the getwbbuserdata function in session.php for Woltlab Burning Board 2.0.3 through 2.3.0 allows remote attackers to execute arbitrary SQL commands via the (1) userid or…
|
NVD-CWE-Other
|
CVE-2005-0661
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313338
|
4.3 |
MEDIUM
|
mercuryboard
|
mercuryboard
|
Cross-site scripting (XSS) vulnerability in index.php for MercuryBoard 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the Avatar field.
|
NVD-CWE-Other
|
CVE-2005-0662
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313339
|
5.1 |
MEDIUM
|
john_bradley
|
xv
|
Format string vulnerability in xv before 3.10a allows remote attackers to execute arbitrary code via format string specifiers in a filename.
|
NVD-CWE-Other
|
CVE-2005-0665
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313340
|
4.6 |
MEDIUM
|
the_pax_team
|
pax_linux
|
Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring, allows local users and possibly remote attackers to bypass in…
|
NVD-CWE-Other
|
CVE-2005-0666
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313341
|
5.1 |
MEDIUM
|
sylpheed sylpheed-claws altlinux gentoo redhat
|
sylpheed sylpheed-claws alt_linux linux enterprise_linux fedora_core linux_advanced_workstation
|
Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters t…
|
NVD-CWE-Other
|
CVE-2005-0667
|
2008-09-6 05:46 |
2005-03-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313342
|
7.5 |
HIGH
|
christian_hilgers
|
http_anti_virus_proxy_\(havp\)
|
Unknown vulnerability in HTTP Anti Virus Proxy (HAVP) before 0.51 prevents viruses from being properly detected in certain files such as (1) .CAB or (2) .ZIP files.
|
NVD-CWE-Other
|
CVE-2005-0668
|
2008-09-6 05:46 |
2005-03-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313343
|
7.5 |
HIGH
|
ca3de
|
ca3de
|
Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via format string specifiers in a command.
|
NVD-CWE-Other
|
CVE-2005-0671
|
2008-09-6 05:46 |
2005-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313344
|
7.5 |
HIGH
|
ca3de
|
ca3de
|
Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary code via text strings that are not null terminated, which triggers a null dereference.
|
NVD-CWE-Other
|
CVE-2005-0672
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313345
|
4.3 |
MEDIUM
|
phpbb_group
|
phpbb
|
Cross-site scripting (XSS) vulnerability in usercp_register.php for phpBB 2.0.13 allows remote attackers to inject arbitrary web script or HTML by setting the (1) allowhtml, (2) allowbbcode, or (3) a…
|
NVD-CWE-Other
|
CVE-2005-0673
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313346
|
4.3 |
MEDIUM
|
phpoutsourcing
|
zorum
|
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.5 allows remote attackers to inject arbitrary web script or HTML via the (1) list or (2) frommethod parameters.
|
NVD-CWE-Other
|
CVE-2005-0675
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313347
|
7.5 |
HIGH
|
phpoutsourcing
|
zorum
|
index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.
|
NVD-CWE-Other
|
CVE-2005-0676
|
2008-09-6 05:46 |
2005-05-4 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313348
|
5.0 |
MEDIUM
|
phpoutsourcing
|
zorum
|
index.php for Zorum 3.5 allows remote attackers to perform certain actions as other users by modifying the id parameter.
|
NVD-CWE-Other
|
CVE-2005-0677
|
2008-09-6 05:46 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313349
|
10.0 |
HIGH
|
kde
|
kde
|
Multiple vulnerabilities in fliccd, when installed setuid root as part of the kdeedu Kstars support for Instrument Neutral Distributed Interface (INDI) in KDE 3.3 to 3.3.2, allow local users and remo…
|
NVD-CWE-Other
|
CVE-2005-0011
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313350
|
2.1 |
LOW
|
-
|
-
|
The f2c translator in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-0017
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|