Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-2139 | 1 Pavsta | 1 Pavsta Auto Site | 2011-03-07 | 5.0 MEDIUM | N/A |
PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter. | |||||
CVE-2005-2149 | 1 The Cacti Group | 1 Cacti | 2011-03-07 | 10.0 HIGH | N/A |
config.php in Cacti 0.8.6e and earlier allows remote attackers to set the no_http_headers switch, then modify session information to gain privileges and disable the use of addslashes to conduct SQL injection attacks. | |||||
CVE-2005-2157 | 1 Nabocorp | 1 Nabopoll | 2011-03-07 | 5.0 MEDIUM | N/A |
PHP remote file inclusion vulnerability in survey.inc.php for nabopoll 1.2 allows remote attackers to execute arbitrary PHP code via the path parameter. | |||||
CVE-2005-2170 | 1 Ibm | 1 Tivoli Management Framework | 2011-03-07 | 5.0 MEDIUM | N/A |
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data. | |||||
CVE-2005-2176 | 1 Novell | 1 Netmail | 2011-03-07 | 6.4 MEDIUM | N/A |
Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies. | |||||
CVE-2005-1453 | 1 Leafnode | 1 Leafnode | 2011-03-07 | 5.0 MEDIUM | N/A |
fetchnews in leafnode 1.9.48 to 1.11.1 allows remote NNTP servers to cause a denial of service (crash) by closing the connection while fetchnews is reading (1) an article header or (2) an article body, which also prevents fetchnews from querying other servers. | |||||
CVE-2005-1517 | 1 Cisco | 1 Firewall Services Module | 2011-03-07 | 7.5 HIGH | N/A |
Unknown vulnerability in Cisco Firewall Services Module (FWSM) 2.3.1 and earlier, when using URL, FTP, or HTTPS filtering exceptions, allows certain TCP packets to bypass access control lists (ACLs). | |||||
CVE-2005-1579 | 1 Apple | 1 Quicktime | 2011-03-07 | 5.0 MEDIUM | N/A |
Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker. | |||||
CVE-2005-1603 | 1 Niteenterprises | 1 Remote File Manager | 2011-03-07 | 5.0 MEDIUM | N/A |
NiteEnterprises Remote File Manager 1.0 allows remote attackers to cause a denial of service (crash) via a crafted string to TCP port 7080. | |||||
CVE-2005-1642 | 1 Woltlab | 1 Burning Board | 2011-03-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in the verify_email function in Woltlab Burning Board 2.x and earlier allows remote attackers to execute arbitrary SQL commands via the $email variable. | |||||
CVE-2005-1646 | 1 Fastream | 1 Netfile Ftp Web Server | 2011-03-07 | 7.5 HIGH | N/A |
The default installation of Fastream NETFile FTP/Web Server 7.4.6, which supports FXP, does not require that the IP address in a PORT command be the same as the IP of the logged in user, which allows remote attackers to conduct FTP Bounce attacks to bypass firewall rules or cause a denial of service. | |||||
CVE-2005-1707 | 1 Gentoo | 1 Linux Webapp-config | 2011-03-07 | 4.6 MEDIUM | N/A |
The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file. | |||||
CVE-2005-1709 | 1 Bluecoat | 1 Reporter | 2011-03-07 | 7.5 HIGH | N/A |
Unknown vulnerability in Blue Coat Reporter before 7.1.2 allows remote unauthenticated attackers to add a license. | |||||
CVE-2005-1714 | 1 Netwin | 1 Surgemail | 2011-03-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |||||
CVE-2005-1730 | 1 Novell | 1 Imanager | 2011-03-07 | 9.3 HIGH | N/A |
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112. | |||||
CVE-2005-1741 | 1 Gearbox Software | 1 Halo Combat Evolved | 2011-03-07 | 5.0 MEDIUM | N/A |
Gearbox Software Halo: Combat Evolved 1.6 allows remote attackers to cause a denial of service (infinite loop) via malformed data. | |||||
CVE-2005-1756 | 1 Novell | 1 Netmail | 2011-03-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields. | |||||
CVE-2005-1757 | 1 Novell | 1 Netmail | 2011-03-07 | 7.5 HIGH | N/A |
Buffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code. | |||||
CVE-2005-1758 | 1 Novell | 1 Netmail | 2011-03-07 | 7.5 HIGH | N/A |
Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code. | |||||
CVE-2005-1785 | 1 Zongg | 1 Zongg | 2011-03-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in ad/login.asp in ZonGG 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. |