Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-3782 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2008-09-05 | 2.1 LOW | N/A |
Mac OS X 10.4.3 up to 10.4.6, when loginwindow uses the "Name and password" setting, and the "Show the Restart, Sleep, and Shut Down buttons" option is disabled, allows users with physical access to bypass login and reboot the system by entering ">restart", ">power", or ">shutdown" sequences after the username. | |||||
CVE-2005-3854 | 1 Easypagecms | 1 Easypagecms | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in EasyPageCMS allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |||||
CVE-2005-3856 | 1 Krusader | 1 Krusader | 2008-09-05 | 4.0 MEDIUM | N/A |
The Popular URL capability (popularurls.cpp) in Krusader 1.60.0 and 1.70.0-beta1 saves passwords in cleartext in the krusaderrc file when the user enters URLs containing passwords in the panel URL field, which might allow attackers to access other sites. | |||||
CVE-2005-3901 | 1 Macromedia | 1 Flash Communication Server | 2008-09-05 | 7.8 HIGH | N/A |
Macromedia Flash Communication Server MX 1.0 and 1.5 does not sufficiently validate certain RTMP data, which allows attackers to cause a denial of service (instability or crash), as demonstrated using an alpha release build of Flash Player 8.5 (build 133). | |||||
CVE-2005-3919 | 1 Pblang | 1 Pblang | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in PBLang 4.65 allows remote attackers to inject arbitrary web script or HTML via multiple fields in (1) UCP.php and (2) SendPm.php. | |||||
CVE-2005-3957 | 1 Dotclear | 1 Dotclear | 2008-09-05 | 10.0 HIGH | N/A |
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors. | |||||
CVE-2005-3987 | 1 Tradesoft | 1 Tradesoft Cms | 2008-09-05 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Tradesoft CMS allow remote attackers to execute arbitrary SQL commands via unspecified attack vectors. | |||||
CVE-2005-3992 | 1 Wineggdropshell | 1 Wineggdropshell | 2008-09-05 | 7.5 HIGH | N/A |
Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) PASS command to the FTP server. | |||||
CVE-2005-4002 | 1 Esi Products | 1 Webeoc | 2008-09-05 | 4.0 MEDIUM | N/A |
WebEOC before 6.0.2 uses the same secret key for all installations, which allows attackers with the key to decrypt data from any WebEOC installation. | |||||
CVE-2005-4025 | 1 Help Desk Reloaded | 1 Free Help Desk | 2008-09-05 | 7.5 HIGH | N/A |
Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user. | |||||
CVE-2005-4028 | 1 Amember | 1 Amember | 2008-09-05 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in aMember allow remote attackers to inject arbitrary web script or HTML via the (1) lamember_login parameter to sendpass.php and (2) login parameter to member.php. | |||||
CVE-2005-4029 | 1 Esi Products | 1 Webeoc | 2008-09-05 | 5.0 MEDIUM | N/A |
WebEOC before 6.0.2 allows remote attackers to obtain valid usernames via the HTML source of the WebEOC login webpage, which could be useful in other attacks such as locking out valid users via brute force methods. | |||||
CVE-2005-3299 | 1 Phpmyadmin | 1 Phpmyadmin | 2008-09-05 | 5.0 MEDIUM | N/A |
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array. | |||||
CVE-2005-3302 | 1 Blender | 1 Blender | 2008-09-05 | 7.5 HIGH | N/A |
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call. | |||||
CVE-2005-3320 | 1 Siteturn | 1 Domain Manager Pro | 2008-09-05 | 2.6 LOW | N/A |
Cross-site scripting (XSS) vulnerability in SiteTurn Domain Manager Pro allows remote attackers to inject arbitrary web script or HTML via the err parameter in the panel script. | |||||
CVE-2005-3326 | 1 Mybulletinboard | 1 Mybulletinboard | 2008-09-05 | 7.5 HIGH | N/A |
SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter. | |||||
CVE-2005-3332 | 1 Belchior Foundry | 1 Vcard | 2008-09-05 | 7.5 HIGH | N/A |
PHP remote file include vulnerability in admin/define.inc.php in Belchior Foundry vCard 2.9 allows remote attackers to execute arbitrary PHP code via the match parameter. | |||||
CVE-2005-3337 | 1 Mantis | 1 Mantis | 2008-09-05 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Mantis before 0.19.3 allow remote attackers to inject arbitrary web script or HTML via (1) unknown vectors involving Javascript and (2) mantis/view_all_set.php. | |||||
CVE-2005-3338 | 1 Mantis | 1 Mantis | 2008-09-05 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in Mantis before 0.19.3, when using reminders, causes Mantis to display the real email addresses of users. | |||||
CVE-2005-3339 | 1 Mantis | 1 Mantis | 2008-09-05 | 7.2 HIGH | N/A |
Mantis before 0.19.3 caches the User ID longer than necessary, which has unknown impact and attack vectors. |