Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-3799 | 1 Phpbb Group | 1 Phpbb | 2016-10-17 | 5.0 MEDIUM | N/A |
phpBB 2.0.18 allows remote attackers to obtain sensitive information via a large SQL query, which generates an error message that reveals SQL syntax or the full installation path. | |||||
CVE-2005-3801 | 1 Counterpane | 1 Passwordsafe | 2016-10-17 | 4.6 MEDIUM | N/A |
CounterPane PasswordSafe 1.x and 2.x allows local users to test possible encryption keys against a subset of the stored key data without performing the more expensive key derivation function (KDF) function, which reduces the search time in brute force attacks. | |||||
CVE-2005-3809 | 1 Linux | 1 Linux Kernel | 2016-10-17 | 7.8 HIGH | N/A |
The nfattr_to_tcp function in ip_conntrack_proto_tcp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via an update message without private protocol information, which triggers a null dereference. | |||||
CVE-2005-3810 | 1 Linux | 1 Linux Kernel | 2016-10-17 | 7.8 HIGH | N/A |
ip_conntrack_proto_icmp.c in ctnetlink in Linux kernel 2.6.14 up to 2.6.14.3 allows attackers to cause a denial of service (kernel oops) via a message without ICMP ID (ICMP_ID) information, which leads to a null dereference. | |||||
CVE-2005-3847 | 1 Linux | 1 Linux Kernel | 2016-10-17 | 4.0 MEDIUM | N/A |
The handle_stop_signal function in signal.c in Linux kernel 2.6.11 up to other versions before 2.6.13 and 2.6.12.6 allows local users to cause a denial of service (deadlock) by sending a SIGKILL to a real-time threaded process while it is performing a core dump. | |||||
CVE-2005-3892 | 1 Gadu-gadu | 1 Gadu-gadu Instant Messenger | 2016-10-17 | 5.0 MEDIUM | N/A |
Gadu-Gadu 7.20 allows remote attackers to eavesdrop on a user via a web page that accesses the EasycallLite.oce ActiveX control, which can initiate an outgoing phone call and listen to the microphone. | |||||
CVE-2005-3896 | 1 Mozilla | 1 Mozilla | 2016-10-17 | 7.8 HIGH | N/A |
Mozilla allows remote attackers to cause a denial of service (CPU consumption) via a Javascript BODY onload event that calls the window function. | |||||
CVE-2005-3897 | 1 Apple | 1 Safari | 2016-10-17 | 7.8 HIGH | N/A |
Apple Safari 2.0.2 allows remote attackers to cause a denial of service (system slowdown) via a Javascript BODY onload event that calls the window function. | |||||
CVE-2005-3543 | 1 Phorum | 1 Phorum | 2016-10-17 | 6.8 MEDIUM | N/A |
SQL injection vulnerability in search.php in Phorum 5.0.0alpha through 5.0.20, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands via the forum_ids parameter. | |||||
CVE-2005-3571 | 1 Codegrrl | 5 Phpcalendar, Phpclique, Phpcurrently and 2 more | 2016-10-17 | 5.0 MEDIUM | N/A |
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently 2.0, (d) PHPFanBase 2.1, and (e) PHPQuotes 1.0 allows remote attackers to include arbitrary local files via the siteurl parameter when register_globals is enabled. NOTE: It was later reported that PHPFanBase 2.2 is also affected. | |||||
CVE-2005-3583 | 1 Sun | 2 Jre, Sdk | 2016-10-17 | 7.8 HIGH | N/A |
(1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on JBoss. | |||||
CVE-2005-3584 | 1 Phpwebthings | 1 Phpwebthings | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in forum.php in PhpWebThings 1.4.4 allows remote attackers to inject arbitrary web script or HTML via the forum parameter. | |||||
CVE-2005-3586 | 1 Mambo | 1 Mambo | 2016-10-17 | 5.0 MEDIUM | N/A |
content.php in Mambo 4.5.2 through 4.5.2.3 allows remote attackers to obtain the installation path of the application via a URL that causes the application to return an error. | |||||
CVE-2005-3592 | 1 Cutephp | 1 Cutenews | 2016-10-17 | 5.0 MEDIUM | N/A |
index.php CuteNews 1.4.0 and earlier allows remote attackers to obtain the path of the installation path of the application by triggering an error message, such as by entering multiple ../ (dot dot slash) in the archive parameter. | |||||
CVE-2005-3594 | 1 E107 | 1 E107 | 2016-10-17 | 5.0 MEDIUM | N/A |
game_score.php in e107 allows remote attackers to insert high scores via HTTP POST methods utilizing the $player_name, $player_score, and $game_name variables. | |||||
CVE-2005-3622 | 1 Phpmyadmin | 1 Phpmyadmin | 2016-10-17 | 5.0 MEDIUM | N/A |
phpMyAdmin 2.7.0-beta1 and earlier allows remote attackers to obtain the full path of the server via direct requests to multiple scripts in the libraries directory. | |||||
CVE-2005-3649 | 1 Moodle | 1 Moodle | 2016-10-17 | 2.6 LOW | N/A |
jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter. | |||||
CVE-2005-3677 | 1 Realnetworks | 1 Realplayer | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file. NOTE: due to the lack of details, it is unclear how this is different than CVE-2005-2629 and CVE-2005-2630, but the vendor advisory implies that it is different. | |||||
CVE-2005-3679 | 1 Activecampaign | 1 1-2-all Broadcast Email | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel. | |||||
CVE-2005-3680 | 1 Xoops | 1 Xoops | 2016-10-17 | 6.4 MEDIUM | N/A |
Directory traversal vulnerability in editor_registry.php in XOOPS 2.2.3 allows remote attackers to read or include arbitrary local files via a .. (dot dot) in the xoopsConfig[language] parameter. |