|
350551
|
4.6 |
MEDIUM
|
-
|
-
|
MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to ac…
|
NVD-CWE-Other
|
CVE-2005-2329
|
2008-09-6 05:51 |
2005-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350552
|
4.3 |
MEDIUM
|
php.warpedweb.net
|
phppageprotect
|
Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a allows remote attackers to inject arbitrary web script or HTML via the username parameter to (1) admin.php or (2) login.php.
|
NVD-CWE-Other
|
CVE-2005-2332
|
2008-09-6 05:51 |
2005-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350553
|
10.0 |
HIGH
|
y.sak
|
y.sak
|
Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.
|
NVD-CWE-Other
|
CVE-2005-2334
|
2008-09-6 05:51 |
2005-07-20 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350554
|
4.3 |
MEDIUM
|
msearch
|
unicode_msearch
|
Cross-site scripting (XSS) vulnerability in the Unicode version of msearch (unicode-msearch) 1.51(U1)-beta1, 1.51(U1), and 1.52(U1) allows remote attackers to inject arbitrary web script or HTML via …
|
NVD-CWE-Other
|
CVE-2005-2339
|
2008-09-6 05:51 |
2005-11-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350555
|
5.0 |
MEDIUM
|
emc
|
navisphere_manager
|
EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).
|
NVD-CWE-Other
|
CVE-2005-2358
|
2008-09-6 05:51 |
2005-08-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350556
|
5.0 |
MEDIUM
|
alwil
|
avast_antivirus
|
Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers…
|
NVD-CWE-Other
|
CVE-2005-2384
|
2008-09-6 05:51 |
2005-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350557
|
7.5 |
HIGH
|
alwil
|
avast_antivirus
|
Buffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to execute arbitr…
|
NVD-CWE-Other
|
CVE-2005-2385
|
2008-09-6 05:51 |
2005-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350558
|
4.3 |
MEDIUM
|
elemental_software
|
cartwiz
|
Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
NVD-CWE-Other
|
CVE-2005-2386
|
2008-09-6 05:51 |
2005-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350559
|
7.5 |
HIGH
|
goodtech_systems
|
goodtech_smtp_server
|
Multiple stack-based buffer overflows in GoodTech SMTP server 5.16 allow remote attackers to execute arbitrary code via (1) a RCPT TO command with a long DNS name, or (2) a large number of RCPT TO co…
|
NVD-CWE-Other
|
CVE-2005-2387
|
2008-09-6 05:51 |
2005-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350560
|
5.0 |
MEDIUM
|
symantec_veritas
|
netbackup_enterprise_server netbackup_server
|
NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference.
|
NVD-CWE-Other
|
CVE-2005-2389
|
2008-09-6 05:51 |
2005-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350561
|
5.0 |
MEDIUM
|
3com
|
3crwe454g72
|
Unknown vulnerability in 3Com OfficeConnect Wireless 11g Access Point before 1.03.12 allows remote attackers to obtain sensitive information via the web interface.
|
NVD-CWE-Other
|
CVE-2005-2391
|
2008-09-6 05:51 |
2005-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350562
|
4.3 |
MEDIUM
|
cutephp
|
cutenews
|
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via (1) the lastusername parameter to index.php or (2) selected_search_arch p…
|
NVD-CWE-Other
|
CVE-2005-2393
|
2008-09-6 05:51 |
2005-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350563
|
5.0 |
MEDIUM
|
cutephp
|
cutenews
|
show_news.php in CuteNews 1.3.6 allows remote attackers to obtain the full path of the server via an invalid archive parameter.
|
NVD-CWE-Other
|
CVE-2005-2394
|
2008-09-6 05:51 |
2005-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350564
|
5.0 |
MEDIUM
|
php_fusion
|
php_fusion
|
PHP-Fusion allows remote attackers to inject arbitrary Cascading Style Sheets (CSS) via the BBCode color tag.
|
NVD-CWE-Other
|
CVE-2005-2401
|
2008-09-6 05:51 |
2005-07-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350565
|
7.5 |
HIGH
|
portailphp
|
portailphp
|
SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "…
|
NVD-CWE-Other
|
CVE-2005-2486
|
2008-09-6 05:51 |
2005-08-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350566
|
7.6 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.
|
NVD-CWE-Other
|
CVE-2005-2501
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350567
|
7.2 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse user…
|
NVD-CWE-Other
|
CVE-2005-2504
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350568
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation.
|
NVD-CWE-Other
|
CVE-2005-2505
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350569
|
5.0 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.
|
NVD-CWE-Other
|
CVE-2005-2506
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350570
|
7.5 |
HIGH
|
apple
|
mac_os_x_server
|
Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
|
NVD-CWE-Other
|
CVE-2005-2507
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350571
|
4.6 |
MEDIUM
|
apple
|
mac_os_x mac_os_x_server
|
dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.
|
NVD-CWE-Other
|
CVE-2005-2508
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350572
|
2.1 |
LOW
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accoun…
|
NVD-CWE-Other
|
CVE-2005-2509
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350573
|
4.6 |
MEDIUM
|
apple
|
mac_os_x_server
|
The Server Admin tool in servermgr_ipfilter for Mac OS X 10.4 to 10.4.2, when using multiple subnets and Address Groups, does not always properly write firewall rules to the Active Rules when certain…
|
NVD-CWE-Other
|
CVE-2005-2510
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350574
|
10.0 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Unknown vulnerability in Mac OS X 10.4.2 and earlier, when using Kerberos authentication with LDAP, allows attackers to gain access to a root Terminal window.
|
NVD-CWE-Other
|
CVE-2005-2511
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350575
|
2.1 |
LOW
|
apple
|
mail mac_os_x
|
Mail.app in Mac OS 10.4.2 and earlier, when printing or forwarding an HTML message, loads remote images even when the user's preferences state otherwise, which could result in a privacy leak.
|
NVD-CWE-Other
|
CVE-2005-2512
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350576
|
5.0 |
MEDIUM
|
apple
|
mac_os_x
|
Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure input fields.
|
NVD-CWE-Other
|
CVE-2005-2513
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350577
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2005-2514
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350578
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Quartz Composer Screen Saver in Mac OS X 10.4.2 allows local users to access links from the RSS Visualizer even when a password is required.
|
NVD-CWE-Other
|
CVE-2005-2515
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350579
|
7.5 |
HIGH
|
apple
|
safari mac_os_x
|
Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arb…
|
NVD-CWE-Other
|
CVE-2005-2516
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350580
|
2.6 |
LOW
|
apple
|
safari mac_os_x
|
Safari in Mac OS X 10.3.9 and 10.4.2 submits forms from an XSL formatted page to the next page that is browsed by the user, which causes form data to be sent to the wrong site.
|
NVD-CWE-Other
|
CVE-2005-2517
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350581
|
7.5 |
HIGH
|
apple
|
mac_os_x
|
Buffer overflow in servermgrd in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
|
NVD-CWE-Other
|
CVE-2005-2518
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350582
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
slpd in Directory Services in Mac OS X 10.3.9 creates insecure temporary files as root, which allows local users to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2519
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350583
|
2.1 |
LOW
|
apple
|
mac_os_x
|
The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allow…
|
NVD-CWE-Other
|
CVE-2005-2520
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350584
|
4.6 |
MEDIUM
|
apple
|
mac_os_x
|
Buffer overflow in traceroute in Mac OS X 10.3.9 allows local users to execute arbitrary code via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-2521
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350585
|
5.1 |
MEDIUM
|
apple
|
safari mac_os_x
|
Safari in WebKit in Mac OS X 10.4 to 10.4.2 directly accesses URLs within PDF files without the normal security checks, which allows remote attackers to execute arbitrary code via links in a PDF file.
|
NVD-CWE-Other
|
CVE-2005-2522
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350586
|
4.3 |
MEDIUM
|
apple
|
weblog_server mac_os_x
|
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-2523
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350587
|
5.0 |
MEDIUM
|
apple
|
safari mac_os_x mac_os_x_server
|
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
|
NVD-CWE-Other
|
CVE-2005-2524
|
2008-09-6 05:51 |
2005-10-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350588
|
5.0 |
MEDIUM
|
easy_software_products apple
|
cups mac_os_x
|
CUPS in Mac OS X 10.3.9 and 10.4.2 does not properly close file descriptors when handling multiple simultaneous print jobs, which allows remote attackers to cause a denial of service (printing halt).
|
NVD-CWE-Other
|
CVE-2005-2525
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350589
|
5.0 |
MEDIUM
|
easy_software_products apple
|
cups mac_os_x
|
CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consumption) by sending a partial IPP request and closing the connection.
|
NVD-CWE-Other
|
CVE-2005-2526
|
2008-09-6 05:51 |
2005-08-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350590
|
7.5 |
HIGH
|
maxwebportal
|
maxwebportal
|
SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.
|
NVD-CWE-Other
|
CVE-2005-1779
|
2008-09-6 05:50 |
2005-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350591
|
5.0 |
MEDIUM
|
mailenable
|
mailenable_enterprise mailenable_professional
|
Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).
|
NVD-CWE-Other
|
CVE-2005-1781
|
2008-09-6 05:50 |
2005-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350592
|
4.3 |
MEDIUM
|
w.m.r._simpson
|
bookreview
|
Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_revi…
|
NVD-CWE-Other
|
CVE-2005-1782
|
2008-09-6 05:50 |
2005-05-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350593
|
7.5 |
HIGH
|
hosting_controller
|
hosting_controller
|
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.
|
NVD-CWE-Other
|
CVE-2005-1784
|
2008-09-6 05:50 |
2005-05-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350594
|
7.5 |
HIGH
|
hosting_controller
|
hosting_controller
|
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.
|
NVD-CWE-Other
|
CVE-2005-1788
|
2008-09-6 05:50 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350595
|
7.5 |
HIGH
|
india_software_solution
|
shopping_cart
|
SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.
|
NVD-CWE-Other
|
CVE-2005-1789
|
2008-09-6 05:50 |
2005-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350596
|
5.0 |
MEDIUM
|
microsoft
|
windows_xp
|
Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can b…
|
NVD-CWE-Other
|
CVE-2005-1792
|
2008-09-6 05:50 |
2005-06-1 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350597
|
5.1 |
MEDIUM
|
openssl
|
openssl
|
The design of Advanced Encryption Standard (AES), aka Rijndael, allows remote attackers to recover AES keys via timing attacks on S-box lookups, which are difficult to perform in constant time in AES…
|
NVD-CWE-Other
|
CVE-2005-1797
|
2008-09-6 05:50 |
2005-05-26 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350598
|
5.0 |
MEDIUM
|
serverscheck
|
monitoring_software
|
Directory traversal vulnerability in ServersCheck Monitoring Software 5.9.0 to 5.10.0 allows remote attackers to read arbitrary files via .. (dot dot) sequences in an HTTP request.
|
NVD-CWE-Other
|
CVE-2005-1798
|
2008-09-6 05:50 |
2005-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350599
|
4.3 |
MEDIUM
|
freestyle
|
wiki wikilite
|
Cross-site scripting (XSS) vulnerability in FreeStyle Wiki 3.5.7 and WikiLite (FSWikiLite) .10 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-1799
|
2008-09-6 05:50 |
2005-05-31 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350600
|
5.0 |
MEDIUM
|
nortel
|
contivity vpn_router_1010 vpn_router_1050 vpn_router_1100 vpn_router_1700 vpn_router_1740 vpn_router_2700 vpn_router_5000 vpn_router_600
|
Nortel VPN Router (aka Contivity) allows remote attackers to cause a denial of service (crash) via an IPsec IKE packet with a malformed ISAKMP header.
|
NVD-CWE-Other
|
CVE-2005-1802
|
2008-09-6 05:50 |
2005-05-27 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|