Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3426 1 Cisco 1 Content Services Switch 11500 2008-09-05 5.0 MEDIUM N/A
Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation.
CVE-2005-3643 1 Ibm 1 Db2 Universal Database 2008-09-05 7.5 HIGH N/A
IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.
CVE-2005-3642 1 Ibm 1 Informix Dynamic Database Server 2008-09-05 7.5 HIGH N/A
IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.
CVE-2005-3302 1 Blender 1 Blender 2008-09-05 7.5 HIGH N/A
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
CVE-2005-3425 1 Gnu 1 Gnump3d 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2005-3424.
CVE-2005-3479 1 Ringtail 1 Casebook 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in login.asp in Ringtail CaseBook 6.1.0 allows remote attackers to inject arbitrary web script or HTML via the users parameter.
CVE-2005-3299 1 Phpmyadmin 1 Phpmyadmin 2008-09-05 5.0 MEDIUM N/A
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to include local files via the $__redirect parameter, possibly involving the subform array.
CVE-2005-3668 1 Internet Key Exchange 1 Internet Key Exchange 2008-09-05 5.0 MEDIUM N/A
Multiple buffer overflows in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts related to denial of service, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of information in the original sources, it is likely that this candidate will be REJECTed once it is known which implementations are actually vulnerable.
CVE-2005-3169 1 Microsoft 1 Windows 2000 2008-09-05 5.0 MEDIUM N/A
Microsoft Windows 2000 before Update Rollup 1 for SP4, when the "audit directory service access" policy is enabled, does not record a 565 event message for File Delete Child operations on an Active Directory object in the security event log, which could allow attackers to conduct unauthorized activities without detection.
CVE-2005-3270 1 Symantec 1 Norton Antivirus 2008-09-05 7.2 HIGH N/A
Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file.
CVE-2005-3170 1 Microsoft 1 Windows 2000 2008-09-05 5.1 MEDIUM N/A
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
CVE-2005-3255 1 Nathan Neulinger 1 Cgiwrap 2008-09-05 5.0 MEDIUM N/A
The (1) cgiwrap and (2) php-cgiwrap packages before 3.9 in Debian GNU/Linux provide access to debugging CGIs under the web document root, which allows remote attackers to obtain sensitive information via direct requests to those CGIs.
CVE-2005-3254 1 Nathan Neulinger 1 Cgiwrap 2008-09-05 10.0 HIGH N/A
The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attackers to execute code as other system UIDs that are greater than the minimum value, which should be 1000 on Debian systems.
CVE-2005-3251 1 Gallery Project 1 Gallery 2008-09-05 6.4 MEDIUM N/A
Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter.
CVE-2005-3277 1 Hp 1 Hp-ux 2008-09-05 10.0 HIGH N/A
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.
CVE-2005-3281 1 Nukefixes 1 Nukefixes 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in NukeFixes 3.1 for PHP-Nuke 7.8 allows remote attackers to include arbitrary files via the file parameter.
CVE-2005-3282 1 Splatt 1 Splatt Forum 2008-09-05 7.5 HIGH N/A
Splatt Forum 3.0 to 3.2 allows remote attackers to bypass authentication via unknown vectors.
CVE-2005-3284 1 Ahnlab 3 Myv3, V3net, V3pro 2004 2008-09-05 7.5 HIGH N/A
Multiple buffer overflows in AhnLab V3 AntiVirus V3Pro 2004 before 6.0.0.488, V3Net for Windows Server 6.0 before 6.0.0.488, and MyV3, with compressed file scanning enabled, allow remote attackers to execute arbitrary code via crafted (1) ALZ, (2) UUE, or (3) XXE archives.
CVE-2005-3285 1 Comersus Open Technologies 1 Comersus Backoffice Plus 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2 parameters.
CVE-2005-3171 1 Microsoft 1 Windows 2000 2008-09-05 4.6 MEDIUM N/A
Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administrators to believe that the system is compliant with the specified settings.
CVE-2005-3287 1 Rockliffe 1 Mailsite Express 2008-09-05 5.0 MEDIUM N/A
Incomplete blacklist vulnerability in Mailsite Express allows remote attackers to upload and possibly execute files via attachments with executable extensions such as ASPX, which are not converted to .TXT like other dangerous extensions, and which can be directly requested from the cache directory.
CVE-2005-3172 1 Microsoft 1 Windows 2000 2008-09-05 5.0 MEDIUM N/A
The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could prevent the string from being null terminated and lead to data corruption or enable buffer overflow attacks.
CVE-2005-3238 1 Sun 1 Solaris 2008-09-05 2.1 LOW N/A
Multiple unspecified vulnerabilities in Solaris 10 SCTP Socket Option Processing allows local users to cause a denial of service (panic) via unspecified attack vectors.
CVE-2005-3288 1 Rockliffe 1 Mailsite Express 2008-09-05 5.0 MEDIUM N/A
Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message.
CVE-2005-3289 1 Ibm 1 Aix 2008-09-05 2.1 LOW N/A
LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
CVE-2005-3291 1 Stani 1 Stanis Python Editor 2008-09-05 4.6 MEDIUM N/A
Stani's Python Editor (SPE) 0.7.5 is installed with world-writable permissions, which allows local users to gain privileges by modifying executable files.
CVE-2005-3173 1 Microsoft 1 Windows 2000 2008-09-05 4.6 MEDIUM N/A
Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intended restrictions.
CVE-2005-3174 1 Microsoft 1 Windows 2000 2008-09-05 4.6 MEDIUM N/A
Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
CVE-2005-3292 1 Xeobook 1 Xeobook 2008-09-05 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93 allow remote attackers to inject arbitrary web script or HTML via Javascript events in tages such as <b>.
CVE-2005-3143 1 4d 1 Webstar 2008-09-05 5.0 MEDIUM N/A
Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP clients on Mac OS X 10.4 Mail 2.
CVE-2005-3144 1 Standards Based Linux Instrumentation 1 Sblim-sfcb 2008-09-05 5.0 MEDIUM N/A
httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service via long HTTP headers.
CVE-2005-3145 1 Standards Based Linux Instrumentation 1 Sblim-sfcb 2008-09-05 5.0 MEDIUM N/A
httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service (resource consumption) by connecting to sblim-sfcb but not sending any data.
CVE-2005-3146 2 Storebackup, Suse 2 Storebackup, Suse Linux 2008-09-05 2.1 LOW N/A
StoreBackup before 1.19 allows local users to perform unauthorized operations on arbitrary files via a symlink attack on temporary files.
CVE-2005-3147 2 Storebackup, Suse 2 Storebackup, Suse Linux 2008-09-05 2.1 LOW N/A
StoreBackup before 1.19 creates the backup root with world-readable permissions, which allows local users to obtain sensitive information.
CVE-2005-3121 1 Eduard Bloch 1 Module-assistant 2008-09-05 2.1 LOW N/A
A rule file in module-assistant before 0.9.10 causes a temporary file to be created insecurely, which allows local users to conduct unauthorized operations.
CVE-2005-3148 2 Storebackup, Suse 2 Storebackup, Suse Linux 2008-09-05 4.6 MEDIUM N/A
StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect ownership.
CVE-2005-3115 1 Mpeg-tools 1 Mpeg-tools 2008-09-05 2.1 LOW N/A
mpeg-tools before 1.5b-r2 creates multiple temporary files insecurely, which allows local users to overwrite arbitrary files via (1) ts.stat, (2) ts.mpg, (3) foobar, (4) blockbar, or (5) foobar[NNN].
CVE-2005-3112 1 Macromedia 1 Breeze 2008-09-05 2.1 LOW N/A
The "reset password" feature in Macromedia Breeze 5.0 stores passwords in plaintext in the database instead of the hash, which allows attackers with access to the database to obtain the passwords.
CVE-2005-3104 1 Six Apart 1 Movable Type 2008-09-05 2.6 LOW N/A
mt-comments.cgi in Movable Type before 3.2 allows attackers to redirect users to other web sites via URLs in comments.
CVE-2005-3103 1 Six Apart 1 Movable Type 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Movable Type before 3.2 allows remote attackers to inject arbitrary web script or HTML via the (1) title, (2) category, (3) body, (4) extended body, and (5) excerpt form fields in new blog entries.
CVE-2005-3102 1 Six Apart 1 Movable Type 2008-09-05 5.0 MEDIUM N/A
The administrative interface in Movable Type allows attackers to upload files with arbitrary extensions under the web root.
CVE-2005-3101 1 Six Apart 1 Movable Type 2008-09-05 5.0 MEDIUM N/A
The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
CVE-2005-3100 1 Astaro 1 Security Linux 2008-09-05 5.0 MEDIUM N/A
Unspecified "PPTP Remote DoS Vulnerability" in Astaro Security Linux 4.027 allows attackers to cause a denial of service.
CVE-2005-3150 1 Weex 1 Weex 2008-09-05 7.5 HIGH N/A
Format string vulnerability in the Log_Flush function in Weex 2.6.1.5, 2.6.1, and possibly other versions allows remote FTP servers to execute arbitrary code via format strings in filenames.
CVE-2005-3097 1 Avi Alkalay 1 Contribute.cgi 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in Avi Alkalay contribute.cgi (aka contribute.pl), dated 16 Jun 2002, allows remote attackers to overwrite arbitrary files via ".." sequences in the contribdir variable.
CVE-2005-3151 1 Blender 1 Blender 2008-09-05 7.5 HIGH N/A
Buffer overflow in blenderplay in Blender Player 2.37a allows attackers to execute arbitrary code via a long command line argument.
CVE-2005-3093 1 Nokia 2 3210, 7610 2008-09-05 5.0 MEDIUM N/A
Nokia 7610 and 3210 phones allows attackers to cause a denial of service via certain characters in the filename of a Bluetooth OBEX transfer.
CVE-2005-3091 1 Mantis 1 Mantis 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Mantis before 1.0.0rc1 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, as identified by bug#0005751 "thraxisp".
CVE-2005-3087 1 Securew2 1 Securew2 2008-09-05 5.0 MEDIUM N/A
The SecureW2 3.0 TLS implementation uses weak random number generators (rand and srand from system time) during generation of the pre-master secret (PMS), which makes it easier for attackers to guess the secret and decrypt sensitive data.
CVE-2005-3086 1 Contentserv 1 Contentserv 2008-09-05 6.4 MEDIUM N/A
Directory traversal vulnerability in admin/about.php in contentServ 3.1 allows remote attackers to read or include arbitrary files via ".." sequences in the ctsWebsite parameter.