|
313351
|
2.1 |
LOW
|
f2c_open_source_project
|
f2c_translator
|
The f2 shell script in the f2c package 3.1 allows local users to read arbitrary files via a symlink attack on temporary files.
|
NVD-CWE-Other
|
CVE-2005-0018
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313352
|
5.0 |
MEDIUM
|
delegate etl
|
delegate
|
The DNS implementation in DeleGate 8.10.2 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could t…
|
NVD-CWE-Other
|
CVE-2005-0036
|
2008-09-6 05:45 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313353
|
5.0 |
MEDIUM
|
dnrd
|
dnrd
|
The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an i…
|
NVD-CWE-Other
|
CVE-2005-0037
|
2008-09-6 05:45 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313354
|
5.0 |
MEDIUM
|
dnrd
|
dnrd
|
This vulnerability is addressed in the following product release:
dnrd, dnrd, 2.10
|
NVD-CWE-Other
|
CVE-2005-0037
|
2008-09-6 05:45 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313355
|
5.0 |
MEDIUM
|
powerdns
|
powerdns
|
The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could t…
|
NVD-CWE-Other
|
CVE-2005-0038
|
2008-09-6 05:45 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313356
|
10.0 |
HIGH
|
tcp
|
tcp
|
The original design of TCP does not check that the TCP sequence number in an ICMP error message is within the range of sequence numbers for data that has been sent but not acknowledged (aka "TCP sequ…
|
NVD-CWE-Other
|
CVE-2005-0065
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313357
|
7.2 |
HIGH
|
synaesthesia
|
synaesthesia
|
Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbit…
|
NVD-CWE-Other
|
CVE-2005-0070
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313358
|
5.0 |
MEDIUM
|
tcp
|
tcp
|
The original design of TCP does not check that the TCP Acknowledgement number in an ICMP error message generated by an intermediate router is within the range of possible values for data that has alr…
|
NVD-CWE-Other
|
CVE-2005-0066
|
2008-09-6 05:45 |
2004-12-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313359
|
5.0 |
MEDIUM
|
tcp
|
tcp
|
The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connec…
|
NVD-CWE-Other
|
CVE-2005-0067
|
2008-09-6 05:45 |
2004-12-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313360
|
5.0 |
MEDIUM
|
tcp
|
tcp
|
The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to forge ICMP error messages for specific TCP connections and c…
|
NVD-CWE-Other
|
CVE-2005-0068
|
2008-09-6 05:45 |
2004-12-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313361
|
4.6 |
MEDIUM
|
debian
|
sympa
|
Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0073
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313362
|
7.2 |
HIGH
|
xpcd
|
xpcd
|
Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-0074
|
2008-09-6 05:45 |
2005-02-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313363
|
4.6 |
MEDIUM
|
abuse
|
abuse-sdl
|
Multiple buffer overflows in the SDL port of abuse (abuse-SDL) before 2.00 allow local users to execute arbitrary code via the command line.
|
NVD-CWE-Other
|
CVE-2005-0098
|
2008-09-6 05:45 |
2005-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313364
|
2.1 |
LOW
|
abuse
|
abuse-sdl
|
The SDL port of abuse (abuse-SDL) before 2.00 does not properly drop privileges before creating certain files, which allows local users to create or overwrite arbitrary files.
|
NVD-CWE-Other
|
CVE-2005-0099
|
2008-09-6 05:45 |
2005-03-8 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313365
|
4.6 |
MEDIUM
|
typespeed
|
typespeed
|
Unknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-0105
|
2008-09-6 05:45 |
2005-02-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313366
|
7.5 |
HIGH
|
debian
|
bsmtpd
|
bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.
|
NVD-CWE-Other
|
CVE-2005-0107
|
2008-09-6 05:45 |
2005-02-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313367
|
2.1 |
LOW
|
checkpoint zonelabs
|
check_point_integrity_client zonealarm zonealarm_wireless_security
|
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify tha…
|
NVD-CWE-Other
|
CVE-2005-0114
|
2008-09-6 05:45 |
2005-02-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313368
|
7.5 |
HIGH
|
awstats
|
awstats
|
AWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the configdir parameter to aswtats.pl.
|
CWE-20
不適切な入力確認
|
CVE-2005-0116
|
2008-09-6 05:45 |
2005-01-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313369
|
4.6 |
MEDIUM
|
xshisen
|
xshisen
|
Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.
|
NVD-CWE-Other
|
CVE-2005-0117
|
2008-09-6 05:45 |
2005-01-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313370
|
2.1 |
LOW
|
helvis
|
helvis
|
helvis 1.8h2_1 and earlier stores recovery files in world readable directories with world readable permissions, which allows local users to read the recovered files of other users.
|
NVD-CWE-Other
|
CVE-2005-0118
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313371
|
2.1 |
LOW
|
helvis
|
helvis
|
helvis 1.8h2_1 and earlier allows local users to recover and read the files of other users via the elvrec setuid program.
|
NVD-CWE-Other
|
CVE-2005-0119
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313372
|
2.1 |
LOW
|
-
|
-
|
helvis 1.8h2_1 and earlier allows local users to delete arbitrary files via the elvprsv setuid program.
|
NVD-CWE-Other
|
CVE-2005-0120
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313373
|
7.5 |
HIGH
|
adobe
|
creative_suite photoshop premiere
|
Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administra…
|
NVD-CWE-Other
|
CVE-2005-0151
|
2008-09-6 05:45 |
2005-06-13 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313374
|
7.5 |
HIGH
|
squirrelmail
|
squirrelmail
|
PHP remote file inclusion vulnerability in Squirrelmail 1.2.6 allows remote attackers to execute arbitrary code via "URL manipulation."
|
NVD-CWE-Other
|
CVE-2005-0152
|
2008-09-6 05:45 |
2005-02-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313375
|
7.5 |
HIGH
|
bidwatcher
|
bidwatcher
|
Format string vulnerability in bidwatcher before 1.3.17 allows remote malicious web servers from eBay, or a spoofed eBay server, to cause a denial of service and possibly execute arbitrary code via c…
|
NVD-CWE-Other
|
CVE-2005-0158
|
2008-09-6 05:45 |
2005-05-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313376
|
5.1 |
MEDIUM
|
e-merge
|
unace
|
Multiple buffer overflows in unace 1.2b allow attackers to execute arbitrary code via (1) 2 overflows in ACE archives, (2) a long command line argument, or (3) certain "Ready for next volume" message…
|
NVD-CWE-Other
|
CVE-2005-0160
|
2008-09-6 05:45 |
2005-02-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313377
|
2.1 |
LOW
|
e-merge
|
unace
|
Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1) ../ sequences or (2) absolute pathnames.
|
NVD-CWE-Other
|
CVE-2005-0161
|
2008-09-6 05:45 |
2005-02-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313378
|
4.6 |
MEDIUM
|
yahoo
|
messenger
|
The Audio Setup Wizard (asw.dll) in Yahoo! Messenger 6.0.0.1750, and possibly other versions, allows attackers to arbitrary code by placing a malicious ping.exe program into the Messenger program dir…
|
NVD-CWE-Other
|
CVE-2005-0242
|
2008-09-6 05:45 |
2005-02-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313379
|
5.0 |
MEDIUM
|
yahoo
|
messenger
|
Yahoo! Messenger 6.0.0.1750, and possibly other versions before 6.0.0.1921, does not properly display long filenames in file dialog boxes, which could allow remote attackers to trick users into downl…
|
NVD-CWE-Other
|
CVE-2005-0243
|
2008-09-6 05:45 |
2005-02-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313380
|
5.0 |
MEDIUM
|
jbrowser
|
jbrowser
|
Directory traversal vulnerability in browser.php in JBrowser 1.0 through 2.1 allows remote attackers to read arbitrary files via the directory parameter. NOTE: the provenance of this information is …
|
CWE-22
パス・トラバーサル
|
CVE-2004-2750
|
2008-09-6 05:45 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313381
|
4.3 |
MEDIUM
|
postnuke_software_foundation
|
postnuke
|
Cross-site scripting (XSS) vulnerability in the Downloads module in PostNuke up to 0.726, and possibly later versions, allows remote attackers to inject arbitrary HTML and web script via the ttitle p…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2004-2752
|
2008-09-6 05:45 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313382
|
7.5 |
HIGH
|
yabb
|
yabb_se
|
SQL injection vulnerability in SSI.php in YaBB SE 1.5.4, 1.5.3, and possibly other versions before 1.5.5 allows remote attackers to execute arbitrary SQL commands via the ID_MEMBER parameter to the (…
|
CWE-89
SQLインジェクション
|
CVE-2004-2754
|
2008-09-6 05:45 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313383
|
4.3 |
MEDIUM
|
xoops
|
xoops
|
Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attackers to inject arbitrary web script or HTML via the (1) forum and (2) topic_id par…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2004-2756
|
2008-09-6 05:45 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313384
|
5.0 |
MEDIUM
|
securecomputing
|
sidewinder_g2
|
Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (CPU consumption) via delayed responses to DNS queries.
|
NVD-CWE-Other
|
CVE-2004-2399
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313385
|
10.0 |
HIGH
|
phpgroupware
|
phpgroupware
|
Unknown "overflow" in the phpgw_config table for phpGroupWare before 0.9.14.002 has unknown attack vectors and impact.
|
NVD-CWE-Other
|
CVE-2004-2406
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313386
|
10.0 |
HIGH
|
phpgroupware
|
phpgroupware
|
Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Config functionality.
|
NVD-CWE-Other
|
CVE-2004-2407
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313387
|
2.1 |
LOW
|
samhain_labs
|
samhain
|
Unknown vulnerability in sh_hash_compdata for Samhain 1.8.9 through 2.0.1 might allow attackers to cause a denial of service (null pointer dereference).
|
NVD-CWE-Other
|
CVE-2004-2410
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313388
|
10.0 |
HIGH
|
axis
|
2100_network_camera 2110_network_camera 2120_network_camera 2130_ptz_network_camera 230_mpeg2_video_server 2400_video_server 2401_video_server 2411_video_server 2420_network_c…
|
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi…
|
NVD-CWE-Other
|
CVE-2004-2427
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313389
|
2.1 |
LOW
|
gnu
|
gnubiff
|
Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.
|
NVD-CWE-Other
|
CVE-2004-2459
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313390
|
5.0 |
MEDIUM
|
securecomputing
|
sidewinder_g2
|
Secure Computing Corporation Sidewinder G2 6.1.0.01 allows remote attackers to cause a denial of service (SMTP proxy failure) via unknown attack vendors involving an "extremely busy network." NOTE: …
|
NVD-CWE-Other
|
CVE-2004-2545
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313391
|
7.5 |
HIGH
|
phpgroupware
|
phpgroupware
|
PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to execute arbitrary PHP code via an external URL in the appdir paramet…
|
NVD-CWE-Other
|
CVE-2004-2573
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313392
|
5.0 |
MEDIUM
|
phpgroupware
|
phpgroupware
|
The acl_check function in phpGroupWare 0.9.16RC2 always returns True, even when mkdir does not behave as expected, which could allow remote attackers to obtain sensitive information via WebDAV from u…
|
NVD-CWE-Other
|
CVE-2004-2577
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313393
|
5.0 |
MEDIUM
|
-
|
-
|
Quake II server before R1Q2, as used in multiple products, allows remote attackers to corrupt the server's client state data structure by exiting a session without a valid disconnect command, then re…
|
NVD-CWE-Other
|
CVE-2004-2598
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313394
|
10.0 |
HIGH
|
vserver
|
linux-vserver
|
Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspecified impact and a…
|
NVD-CWE-Other
|
CVE-2004-2613
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313395
|
5.0 |
MEDIUM
|
paul_l_daniels
|
ripmime
|
The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers, which leads to a buffer underflow.
|
NVD-CWE-Other
|
CVE-2004-2620
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313396
|
7.8 |
HIGH
|
first_virtual_communications
|
click_to_meet_express click_to_meet_premier conference_server v-gate
|
Multiple vulnerabilities in the H.323 protocol implementation for First Virtual Communications Click to Meet Express (when used with H.323 conferencing endpoints), Click to Meet Premier, Conference S…
|
NVD-CWE-Other
|
CVE-2004-2629
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313397
|
4.9 |
MEDIUM
|
apache
|
james
|
Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock fr…
|
NVD-CWE-Other
|
CVE-2004-2650
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313398
|
7.5 |
HIGH
|
pd9_software
|
megabbs
|
Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.1 allows attackers to gain privileges via unknown vectors involving (1) admin/userlevelmembers-edit.asp and (2) admin/edit-groups.asp.
|
NVD-CWE-Other
|
CVE-2004-2653
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313399
|
5.0 |
MEDIUM
|
squid
|
squid
|
The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigge…
|
NVD-CWE-Other
|
CVE-2004-2654
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313400
|
2.1 |
LOW
|
suse
|
suse_linux
|
resmgr in SUSE CORE 9 does not properly identify terminal names, which allows local users to spoof terminals and login types.
|
NVD-CWE-Other
|
CVE-2004-2658
|
2008-09-6 05:44 |
2004-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|