Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-2299 | 1 Man And Machine Ltd. | 1 Simple Message Board | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2) UID parameter to user.cfm, (3) TID parameter to thread.cfm, or (4) PostDate parameter to search.cfm. | |||||
CVE-2005-2300 | 1 Skype Technologies | 1 Skype | 2016-10-17 | 2.1 LOW | N/A |
Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file. | |||||
CVE-2005-2301 | 1 Powerdns | 1 Powerdns | 2016-10-17 | 5.0 MEDIUM | N/A |
PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack. | |||||
CVE-2005-2302 | 1 Powerdns | 1 Powerdns | 2016-10-17 | 2.1 LOW | N/A |
PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion. | |||||
CVE-2005-2338 | 1 Xoops | 1 Xoops | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in the forum module. | |||||
CVE-2005-2346 | 1 Novell | 1 Groupwise | 2016-10-17 | 7.5 HIGH | N/A |
Buffer overflow in Novell GroupWise 6.5 Client allows remote attackers to execute arbitrary code via a GWVW02xx.INI language file with a long entry, as demonstrated using a long ES02TKS.VEW value in the Group Task section. | |||||
CVE-2005-2372 | 1 Oracle | 1 Forms | 2016-10-17 | 7.2 HIGH | N/A |
Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet. | |||||
CVE-2005-2373 | 1 Whitsoft Development | 1 Slimftpd | 2016-10-17 | 7.2 HIGH | N/A |
Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands. | |||||
CVE-2005-2375 | 1 Codemasters | 1 Toca Race Driver | 2016-10-17 | 5.0 MEDIUM | N/A |
Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message. | |||||
CVE-2005-2376 | 1 Codemasters | 1 Toca Race Driver | 2016-10-17 | 5.0 MEDIUM | N/A |
Buffer overflow in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via a long (1) nickname or (2) chat message. | |||||
CVE-2005-2379 | 1 Oracle | 1 Reports | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports 9.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) debug parameter to showenv, (2) test parameter to parsequery, or (3) delimiter or (4) CELLWRAPPER parameter to rwservlet. | |||||
CVE-2005-2380 | 1 Php Surveyor | 1 Php Surveyor | 2016-10-17 | 5.0 MEDIUM | N/A |
Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters to browse.php, or the sid parameter to (4) dataentry.php or (5) export.php. | |||||
CVE-2005-2381 | 1 Php Surveyor | 1 Php Surveyor | 2016-10-17 | 5.0 MEDIUM | N/A |
PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) database.php, (5) sessioncontrol.php, (6) html.php, (7) sessioncontrol.php, an invalid (8) qid parameter to dumpquestion.php, or an invalid lid parameter to (9) labels.php or (10) dumplabel.php, which reveal the path in an error message. | |||||
CVE-2005-2382 | 1 Oray | 1 Peanuthull | 2016-10-17 | 7.2 HIGH | N/A |
Oray PeanutHull 3.0.1.0 and earlier does not properly drop SYSTEM privileges when launched from the system tray, which allows local users to gain privileges by accessing the Help functionality. | |||||
CVE-2005-2383 | 1 Phpnews | 1 Phpnews | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request. | |||||
CVE-2005-2390 | 1 Proftpd Project | 1 Proftpd | 2016-10-17 | 6.4 MEDIUM | N/A |
Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftpshut, or (2) the SQLShowInfo mod_sql directive. | |||||
CVE-2005-2399 | 1 Php Surveyor | 1 Php Surveyor | 2016-10-17 | 7.5 HIGH | N/A |
PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php. | |||||
CVE-2005-2422 | 1 Beehive Forum | 1 Beehive Forum | 2016-10-17 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter. | |||||
CVE-2005-2107 | 1 Wordpress | 1 Wordpress | 2016-10-17 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter. | |||||
CVE-2005-2108 | 1 Wordpress | 1 Wordpress | 2016-10-17 | 7.5 HIGH | N/A |
SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file. |