|
349701
|
5.0 |
MEDIUM
|
clam_anti-virus
|
clamav
|
libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable.
|
CWE-399 CWE-17
リソース管理の問題 コード
|
CVE-2005-2919
|
2017-07-11 10:33 |
2005-09-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349702
|
7.5 |
HIGH
|
clam_anti-virus
|
clamav
|
Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to execute arbitrary code via a crafted UPX packed executable.
|
NVD-CWE-Other
|
CVE-2005-2920
|
2017-07-11 10:33 |
2005-09-21 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349703
|
7.2 |
HIGH
|
checkpoint
|
zonealarm zonealarm_security_suite
|
Multiple Check Point Zone Labs ZoneAlarm products before 7.0.362, including ZoneAlarm Security Suite 5.5.062.004 and 6.5.737, use insecure default permissions for critical files, which allows local u…
|
CWE-264
認可・権限・アクセス制御
|
CVE-2005-2932
|
2017-07-11 10:33 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349704
|
7.2 |
HIGH
|
sco
|
unixware
|
Unspecified vulnerability in ptrace in SCO UnixWare 7.1.3 and 7.1.4 allows local users to gain privileges via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2005-2934
|
2017-07-11 10:33 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349705
|
7.5 |
HIGH
|
davide_libenzi
|
xmail
|
Stack-based buffer overflow in sendmail in XMail before 1.22 allows remote attackers to execute arbitrary code via a long -t command line option.
|
NVD-CWE-Other
|
CVE-2005-2943
|
2017-07-11 10:33 |
2005-10-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349706
|
5.1 |
MEDIUM
|
killprocess
|
killprocess
|
Buffer overflow in KillProcess 2.20 and earlier allows user-assisted attackers to execute arbitrary code via an exe file with a long FileDescription in the version resource.
|
NVD-CWE-Other
|
CVE-2005-2947
|
2017-07-11 10:33 |
2005-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349707
|
4.3 |
MEDIUM
|
sawmill
|
sawmill
|
Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request.
|
NVD-CWE-Other
|
CVE-2005-2950
|
2017-07-11 10:33 |
2005-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349708
|
7.5 |
HIGH
|
azerbaijan_development_group
|
azdgdating
|
Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP commands via ".." sequences and "%00" (t…
|
NVD-CWE-Other
|
CVE-2005-2951
|
2017-07-11 10:33 |
2005-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349709
|
5.0 |
MEDIUM
|
subscribe_me_pro
|
subscribe_me_pro
|
Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.
|
NVD-CWE-Other
|
CVE-2005-2952
|
2017-07-11 10:33 |
2005-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349710
|
7.5 |
HIGH
|
adaptive_technology_resource_centre
|
atutor
|
SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the email field.
|
NVD-CWE-Other
|
CVE-2005-2954
|
2017-07-11 10:33 |
2005-09-17 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349711
|
2.1 |
LOW
|
gnu debian
|
cfengine debian_linux
|
cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.
|
NVD-CWE-Other
|
CVE-2005-2960
|
2017-07-11 10:33 |
2005-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349712
|
7.5 |
HIGH
|
prozilla
|
prozilla_download_accelerator
|
Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers to execute arbitrary code via a search response w…
|
NVD-CWE-Other
|
CVE-2005-2961
|
2017-07-11 10:33 |
2005-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349713
|
7.5 |
HIGH
|
mod_auth_shadow
|
mod_auth_shadow
|
The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication…
|
NVD-CWE-Other
|
CVE-2005-2963
|
2017-07-11 10:33 |
2005-10-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349714
|
7.5 |
HIGH
|
abisource
|
community_abiword
|
Stack-based buffer overflow in AbiWord before 2.2.10 allows attackers to execute arbitrary code via the RTF import mechanism.
|
NVD-CWE-Other
|
CVE-2005-2964
|
2017-07-11 10:33 |
2005-09-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349715
|
7.5 |
HIGH
|
xine
|
xine-lib
|
Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in met…
|
NVD-CWE-Other
|
CVE-2005-2967
|
2017-07-11 10:33 |
2005-10-14 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349716
|
4.6 |
MEDIUM
|
data_center_resources
|
avocent
|
Avocent CCM console server running firmware 2.1 CCM4850 allows remote authenticated attackers to bypass port restrictions by connecting to the server via SSH and using the connect command to access t…
|
NVD-CWE-Other
|
CVE-2005-2984
|
2017-07-11 10:33 |
2005-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349717
|
7.5 |
HIGH
|
aewebworks
|
aedating
|
SQL injection vulnerability in search_result.php in AEwebworks aeDating Script 4.0 and earlier allows remote attackers to execute arbitrary SQL statements via the Country parameter.
|
NVD-CWE-Other
|
CVE-2005-2985
|
2017-07-11 10:33 |
2005-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349718
|
7.5 |
HIGH
|
ahnlab
|
v3_virusblock_2005 v3net v3pro_2004
|
The v3flt2k.sys driver in AhnLab V3Pro 2004 Build 6.0.0.383, V3 VirusBlock 2005 Build 6.0.0.383, V3Net for Windows Server 6.0 Build 6.0.0.383 does not properly validate the source of the DeviceIoCont…
|
NVD-CWE-Other
|
CVE-2005-2986
|
2017-07-11 10:33 |
2005-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349719
|
7.5 |
HIGH
|
digital_scribe
|
digital_scribe
|
SQL injection vulnerability in login.php in Digital Scribe 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.
|
NVD-CWE-Other
|
CVE-2005-2987
|
2017-07-11 10:33 |
2005-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349720
|
5.0 |
MEDIUM
|
hp
|
laserjet_2430
|
HP LaserJet 2430, and possibly other printers that use Jetdirect controls, stores information about recently printed documents without proper protection, which could allow remote attackers to obtain …
|
NVD-CWE-Other
|
CVE-2005-2988
|
2017-07-11 10:33 |
2005-09-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349721
|
7.5 |
HIGH
|
interakt
|
mx_shop
|
SQL injection vulnerability in Interakt MX Shop 3.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_prd parameters to the pages module in index.php.
|
NVD-CWE-Other
|
CVE-2005-3004
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349722
|
5.0 |
MEDIUM
|
opera
|
opera_browser
|
The mail client in Opera before 8.50 opens attached files from the user's cache directory without warning the user, which might allow remote attackers to inject arbitrary web script and spoof attachm…
|
NVD-CWE-Other
|
CVE-2005-3006
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349723
|
4.6 |
MEDIUM
|
suse
|
suse_linux
|
Buffer overflow in liby2util in Yet another Setup Tool (YaST) for SuSE Linux 9.3 allows local users to execute arbitrary code via a long Loc entry.
|
NVD-CWE-Other
|
CVE-2005-3013
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349724
|
5.0 |
MEDIUM
|
apple
|
safari
|
Apple Safari allows remote attackers to cause a denial of service (application crash) via a crafted data:// URL.
|
NVD-CWE-Other
|
CVE-2005-3018
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349725
|
7.5 |
HIGH
|
jelsoft
|
vbulletin
|
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL commands via the (1) request parameter to joinrequests.php, (2) limitnumber or (3) lim…
|
NVD-CWE-Other
|
CVE-2005-3019
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349726
|
4.3 |
MEDIUM
|
jelsoft
|
vbulletin
|
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) group parameter to css.php, (2) redirect parame…
|
NVD-CWE-Other
|
CVE-2005-3020
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349727
|
2.1 |
LOW
|
jelsoft
|
vbulletin
|
image.php in vBulletin 3.0.9 and earlier allows remote attackers with access to the administrator panel to upload arbitrary files via the upload action.
|
NVD-CWE-Other
|
CVE-2005-3021
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349728
|
5.0 |
MEDIUM
|
alstrasoft
|
epay
|
Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter.
|
NVD-CWE-Other
|
CVE-2005-3026
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349729
|
5.0 |
MEDIUM
|
sybari
|
antigen
|
Sybari Antigen 8.0 SR2 does not properly filter SMTP messages, which allows remote attackers to bypass custom filter rules and send file attachments of arbitrary file types via a message with a subje…
|
NVD-CWE-Other
|
CVE-2005-3027
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349730
|
7.5 |
HIGH
|
mall23
|
mall23
|
SQL injection vulnerability in AddItem.asp in Mall23 eCommerce allows remote attackers to execute arbitrary SQL commands via the idOption_Dropdown_2 parameter.
|
NVD-CWE-Other
|
CVE-2005-3043
|
2017-07-11 10:33 |
2005-09-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349731
|
5.0 |
MEDIUM
|
phpmyfaq
|
phpmyfaq
|
PhpMyFaq 1.5.1 stores data files under the web document root with insufficient access control and predictable filenames, which allows remote attackers to obtain sensitive information via a direct req…
|
NVD-CWE-Other
|
CVE-2005-3049
|
2017-07-11 10:33 |
2005-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349732
|
9.3 |
HIGH
|
igor_pavlov
|
7-zip
|
Stack-based buffer overflow in the ARJ plugin (arj.dll) 3.9.2.0 for 7-Zip 3.13, 4.23, and 4.26 BETA, as used in products including Turbo Searcher, allows remote attackers to execute arbitrary code vi…
|
CWE-119
バッファエラー
|
CVE-2005-3051
|
2017-07-11 10:33 |
2005-09-24 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349733
|
10.0 |
HIGH
|
fortinet
|
fortios fortigate
|
The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Fortinet FTP anti-virus engine by sending a STOR comman…
|
NVD-CWE-noinfo
|
CVE-2005-3057
|
2017-07-11 10:33 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349734
|
7.2 |
HIGH
|
ibm
|
aix
|
Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows local users to execute arbitrary code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3060
|
2017-07-11 10:33 |
2005-10-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349735
|
7.5 |
HIGH
|
interchange_development_group
|
interchange
|
SQL injection vulnerability in pages/forum/submit.html in Interchange 4.9.3 up to 5.2.0 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-3072
|
2017-07-11 10:33 |
2005-09-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349736
|
5.0 |
MEDIUM
|
interchange_development_group
|
interchange
|
Unspecified vulnerability in Interchange 5.0.1 allows attackers 4.9.3, 5.0 before 5.0.2, and 5.2, when a catalog has been created using the (1) "mike", (2) "standard", or (3) "foundation" demo, allow…
|
NVD-CWE-Other
|
CVE-2005-3073
|
2017-07-11 10:33 |
2005-09-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349737
|
7.5 |
HIGH
|
-
|
-
|
SQL injection vulnerability in admin.php in SEO-Board 1.0.2 allows remote attackers to execute arbitrary SQL commands via the user_pass_sha1 value in a cookie.
|
NVD-CWE-Other
|
CVE-2005-3082
|
2017-07-11 10:33 |
2005-09-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349738
|
7.5 |
HIGH
|
avi_alkalay
|
man_cgi
|
Avi Alkalay man-cgi script allows remote attackers to execute arbitrary code via shell metacharacters in the topic parameter.
|
NVD-CWE-Other
|
CVE-2005-3094
|
2017-07-11 10:33 |
2005-09-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349739
|
7.5 |
HIGH
|
avi_alkalay
|
notify
|
Avi Alkalay notify program, dated 19 Aug 2001, allows remote attackers to execute arbitrary commands via shell metacharacters in the from parameter.
|
NVD-CWE-Other
|
CVE-2005-3095
|
2017-07-11 10:33 |
2005-09-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349740
|
7.5 |
HIGH
|
avi_alkalay
|
nslookup.cgi
|
Avi Alkalay nslookup.cgi program, dated 16 June 2002, allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter.
|
NVD-CWE-Other
|
CVE-2005-3096
|
2017-07-11 10:33 |
2005-09-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349741
|
2.1 |
LOW
|
debian
|
backupninja
|
The handler code for backupninja 0.8 and earlier creates temporary files with predictable filenames, which allows local users to modify arbitrary files via a symlink attack.
|
NVD-CWE-Other
|
CVE-2005-3111
|
2017-07-11 10:33 |
2005-09-30 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349742
|
10.0 |
HIGH
|
symantec_veritas
|
netbackup
|
Stack-based buffer overflow in a shared library as used by the Volume Manager daemon (vmd) in VERITAS NetBackup Enterprise Server 5.0 MP1 to MP5 and 5.1 up to MP3A allows remote attackers to execute …
|
NVD-CWE-Other
|
CVE-2005-3116
|
2017-07-11 10:33 |
2005-11-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349743
|
10.0 |
HIGH
|
symantec_veritas
|
netbackup
|
Failed exploit attempts may result in a denial-of-service condition.
|
NVD-CWE-Other
|
CVE-2005-3116
|
2017-07-11 10:33 |
2005-11-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349744
|
1.9 |
LOW
|
antiword
|
antiword
|
The (1) kantiword (kantiword.sh) and (2) gantiword (gantiword.sh) scripts in antiword 0.35 and earlier allow local users to overwrite arbitrary files via a symlink attack on temporary (a) output and …
|
CWE-59
リンク解釈の問題
|
CVE-2005-3126
|
2017-07-11 10:33 |
2005-12-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349745
|
4.3 |
MEDIUM
|
lucidcms
|
lucidcms
|
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.
|
NVD-CWE-Other
|
CVE-2005-3127
|
2017-07-11 10:33 |
2005-10-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349746
|
4.3 |
MEDIUM
|
squirrelmail
|
address_add_plugin
|
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.
|
NVD-CWE-Other
|
CVE-2005-3128
|
2017-07-11 10:33 |
2005-10-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349747
|
5.1 |
MEDIUM
|
s9y
|
serendipity
|
Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin…
|
NVD-CWE-Other
|
CVE-2005-3129
|
2017-07-11 10:33 |
2005-10-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349748
|
5.0 |
MEDIUM
|
virtools
|
web_player
|
Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename.
|
NVD-CWE-Other
|
CVE-2005-3136
|
2017-07-11 10:33 |
2005-10-5 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349749
|
2.1 |
LOW
|
gnu
|
cfengine
|
The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.
|
NVD-CWE-Other
|
CVE-2005-3137
|
2017-07-11 10:33 |
2005-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349750
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed products via the config.cgi file, which is access…
|
NVD-CWE-Other
|
CVE-2005-3138
|
2017-07-11 10:33 |
2005-10-6 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|