Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3163 1 Polipo 1 Polipo 2008-09-05 5.0 MEDIUM N/A
Unspecified vulnerability in Polipo 0.9.8 and earlier allows attackers to read files outside of the web root.
CVE-2005-3165 1 Mediawiki 1 Mediawiki 2008-09-05 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in MediaWiki before 1.4.9 allow remote attackers to inject arbitrary web script or HTML via (1) <math> tags or (2) Extension or <nowiki> sections that "bypass HTML style attribute restrictions" that are intended to protect against XSS vulnerabilities in Internet Explorer clients.
CVE-2005-3166 1 Mediawiki 1 Mediawiki 2008-09-05 5.0 MEDIUM N/A
Unspecified vulnerability in "edit submission handling" for MediaWiki 1.4.x before 1.4.10 and 1.3.x before 1.3.16 allows remote attackers to cause a denial of service (corruption of the previous submission) via a crafted URL.
CVE-2005-3167 1 Mediawiki 1 Mediawiki 2008-09-05 4.3 MEDIUM N/A
Incomplete blacklist vulnerability in MediaWiki before 1.4.11 does not properly remove certain CSS inputs (HTML inline style attributes) that are processed as active content by Internet Explorer, which allows remote attackers to conduct cross-site scripting (XSS) attacks.
CVE-2005-3168 1 Microsoft 1 Windows 2000 2008-09-05 7.5 HIGH N/A
The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.
CVE-2005-3268 1 Raphael Bossek 1 Yiff Server 2008-09-05 2.1 LOW N/A
yiff server (yiff-server) 2.14.2 on Debian GNU/Linux runs as root and does not properly verify ownership of files that it opens, which allows local users to read arbitrary files.
CVE-2005-3270 1 Symantec 1 Norton Antivirus 2008-09-05 7.2 HIGH N/A
Untrusted search path vulnerability in DiskMountNotify for Symantec Norton AntiVirus 9.0.3 allows local users to gain privileges by modifying the PATH to reference a malicious (1) ps or (2) grep file.
CVE-2005-3277 1 Hp 1 Hp-ux 2008-09-05 10.0 HIGH N/A
The LPD service in HP-UX 10.20 11.11 (11i) and earlier allows remote attackers to execute arbitrary code via shell metacharacters ("`" or single backquote) in a request that is not properly handled when an error occurs, as demonstrated by killing the connection, a different vulnerability than CVE-2002-1473.
CVE-2005-3281 1 Nukefixes 1 Nukefixes 2008-09-05 5.0 MEDIUM N/A
Directory traversal vulnerability in NukeFixes 3.1 for PHP-Nuke 7.8 allows remote attackers to include arbitrary files via the file parameter.
CVE-2005-3282 1 Splatt 1 Splatt Forum 2008-09-05 7.5 HIGH N/A
Splatt Forum 3.0 to 3.2 allows remote attackers to bypass authentication via unknown vectors.
CVE-2005-3284 1 Ahnlab 3 Myv3, V3net, V3pro 2004 2008-09-05 7.5 HIGH N/A
Multiple buffer overflows in AhnLab V3 AntiVirus V3Pro 2004 before 6.0.0.488, V3Net for Windows Server 6.0 before 6.0.0.488, and MyV3, with compressed file scanning enabled, allow remote attackers to execute arbitrary code via crafted (1) ALZ, (2) UUE, or (3) XXE archives.
CVE-2005-3285 1 Comersus Open Technologies 1 Comersus Backoffice Plus 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows remote attackers to inject arbitrary web script or HTML via the (1) forwardTo1, (2) forwardTo2, (3) nameFT1, or (4) nameFT2 parameters.
CVE-2005-3287 1 Rockliffe 1 Mailsite Express 2008-09-05 5.0 MEDIUM N/A
Incomplete blacklist vulnerability in Mailsite Express allows remote attackers to upload and possibly execute files via attachments with executable extensions such as ASPX, which are not converted to .TXT like other dangerous extensions, and which can be directly requested from the cache directory.
CVE-2005-3288 1 Rockliffe 1 Mailsite Express 2008-09-05 5.0 MEDIUM N/A
Mailsite Express allows remote attackers to upload and execute files with executable extensions such as ASP by attaching the file using the "compose page" feature, then accessing the file from the cache directory before saving or sending the message.
CVE-2005-3289 1 Ibm 1 Aix 2008-09-05 2.1 LOW N/A
LSCFG in IBM AIX 5.2 and 5.3 does not create temporary files securely, which allows local users to corrupt /etc/passwd and possibly other system files via the trace file.
CVE-2005-3291 1 Stani 1 Stanis Python Editor 2008-09-05 4.6 MEDIUM N/A
Stani's Python Editor (SPE) 0.7.5 is installed with world-writable permissions, which allows local users to gain privileges by modifying executable files.
CVE-2005-3292 1 Xeobook 1 Xeobook 2008-09-05 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93 allow remote attackers to inject arbitrary web script or HTML via Javascript events in tages such as <b>.
CVE-2005-3174 1 Microsoft 1 Windows 2000 2008-09-05 4.6 MEDIUM N/A
Microsoft Windows 2000 before Update Rollup 1 for SP4 allows users to log on to the domain, even when their password has expired, if the fully qualified domain name (FQDN) is 8 characters long.
CVE-2005-3173 1 Microsoft 1 Windows 2000 2008-09-05 4.6 MEDIUM N/A
Microsoft Windows 2000 before Update Rollup 1 for SP4 does not apply group policies if the user logs on using UPN credentials with a trailing dot, which prevents Windows 2000 from finding the correct domain controller and could allow the user to bypass intended restrictions.
CVE-2005-3172 1 Microsoft 1 Windows 2000 2008-09-05 5.0 MEDIUM N/A
The WideCharToMultiByte function in Microsoft Windows 2000 before Update Rollup 1 for SP4 does not properly convert strings with Japanese composite characters in the last character, which could prevent the string from being null terminated and lead to data corruption or enable buffer overflow attacks.
CVE-2005-3171 1 Microsoft 1 Windows 2000 2008-09-05 4.6 MEDIUM N/A
Microsoft Windows 2000 before Update Rollup 1 for SP4 records Event ID 1704 to indicate that Group Policy security settings were successfully updated, even when the processing fails such as when Ntuser.pol cannot be accessed, which could cause system administrators to believe that the system is compliant with the specified settings.
CVE-2005-3170 1 Microsoft 1 Windows 2000 2008-09-05 5.1 MEDIUM N/A
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
CVE-2005-3068 1 Eric Integrated Development Environment 1 Eric Integrated Development Environment 2008-09-05 10.0 HIGH N/A
Unspecified vulnerability in Eric Integrated Development Environment (eric3) before 3.7.2 has unknown impact and attack vectors related to a "potential security exploit."
CVE-2005-3069 1 Hylafax 1 Hylafax 2008-09-05 2.1 LOW N/A
xferfaxstats in HylaFax 4.2.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file.
CVE-2005-3070 1 Hylafax 1 Hylafax 2008-09-05 3.6 LOW N/A
HylaFax 4.2.1 and earlier does not create or verify ownership of the UNIX domain socket, which might allow local users to read faxes and cause a denial of service by creating the socket using the hyla.unix temporary file.
CVE-2005-3076 1 Simplog 1 Simplog 2008-09-05 7.5 HIGH N/A
Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid, (3) cid, or (4) m parameters to archive.php, or the (5) blogid parameter to blogadmin.php.
CVE-2005-3077 1 Microsoft 1 Ie For Macintosh 2008-09-05 5.0 MEDIUM N/A
Microsoft Internet Explorer 5.2.3 for Mac OS allows remote attackers to cause a denial of service (crash) via a web page with malformed attributes in a BGSOUND tag, possibly involving double-quotes in an about: URI.
CVE-2005-3078 1 Punbb 1 Punbb 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PunBB before 1.2.8 allows remote attackers to inject arbitrary web script or HTML via the "forgotten e-mail" feature.
CVE-2005-3079 1 Punbb 1 Punbb 2008-09-05 4.6 MEDIUM N/A
PunBB before 1.2.8 allows remote attackers to perform "code inclusion" via the user language selection.
CVE-2005-3080 1 Geshi 1 Geshi 2008-09-05 5.0 MEDIUM N/A
contrib/example.php in GeSHi before 1.0.7.3 allows remote attackers to read arbitrary files via the language field without a source field set.
CVE-2005-3064 1 Multitheftauto 1 Multitheftauto 2008-09-05 5.0 MEDIUM N/A
MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows remote attackers to change or delete the message of the day (motd.txt).
CVE-2005-3101 1 Six Apart 1 Movable Type 2008-09-05 5.0 MEDIUM N/A
The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.
CVE-2005-2610 1 Vegadns 1 Vegadns 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CVE-2005-2811 1 Net-snmp 1 Net-snmp 2008-09-05 4.6 MEDIUM N/A
Untrusted search path vulnerability in Net-SNMP 5.2.1.2 and earlier, on Gentoo Linux, installs certain Perl modules with an insecure DT_RPATH, which could allow local users to gain privileges.
CVE-2005-2770 1 Wrq 1 Wrq Reflection For Secure It Windows Server 2008-09-05 7.5 HIGH N/A
WRQ Reflection for Secure IT Windows Server 6.0 (formerly known as F-Secure SSH server) does not properly handle when the Windows Administrator or Guest accounts are renamed after SSH key authentication has been configured, which allows remote attackers to use the original names during login.
CVE-2005-2617 1 Linux 1 Linux Kernel 2008-09-05 3.6 LOW N/A
The syscall32_setup_pages function in syscall32.c for Linux kernel 2.6.12 and later, on the 64-bit x86 platform, does not check the return value of the insert_vm_struct function, which allows local users to trigger a memory leak via a 32-bit application with crafted ELF headers.
CVE-2005-2642 1 Mutt 1 Mutt 2008-09-05 7.5 HIGH N/A
Buffer overflow in the mutt_decode_xbit function in Handler.c for Mutt 1.5.10 allows remote attackers to execute arbitrary code, possibly due to interactions with libiconv or gettext.
CVE-2005-2644 1 Isemarket 1 Jaguarcontrol 2008-09-05 7.5 HIGH N/A
Buffer overflow in JaguarEditControl.dll in Isemarket JaguarControl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Jtext field.
CVE-2005-2650 1 Emefa 1 Emefa Guestbook 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in sign.asp in Emefa Guestbook 1.2 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) location, and (3) email parameters.
CVE-2005-2916 1 Linksys 1 Wrt54g 2008-09-05 5.0 MEDIUM N/A
Linksys WRT54G 3.01.03, 3.03.6, 4.00.7, and possibly other versions before 4.20.7, does not verify user authentication until after an HTTP POST request has been processed, which allows remote attackers to (1) modify configuration using restore.cgi or (2) upload new firmware using upgrade.cgi.
CVE-2005-2915 1 Linksys 1 Wrt54g 2008-09-05 5.0 MEDIUM N/A
ezconfig.asp in Linksys WRT54G router 3.01.03, 3.03.6, non-default configurations of 2.04.4, and possibly other versions, uses weak encryption (XOR encoding with a fixed byte mask) for configuration information, which could allow attackers to decrypt the information and possibly re-encrypt it in conjunction with CVE-2005-2914.
CVE-2005-2868 1 Ziptorrent 1 Ziptorrent 2008-09-05 2.1 LOW N/A
ZipTorrent 1.3.7.3 stores sensitive information in plaintext in the pref.txt file, which allows local users to obtain sensitive information such as proxy server information and passwords.
CVE-2005-2867 1 Bluewhalecrm 1 Bluewhalecrm 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in BlueWhaleCRM allows remote attackers to execute arbitrary SQL commands via the Account ID field.
CVE-2005-2866 1 Mercora 1 Imradio 2008-09-05 4.6 MEDIUM N/A
Mercora IMRadio 4.0.0.0 stores usernames and passwords in plaintext in the MercoraClient\Profiles registry key, which allows local users to gain privileges.
CVE-2005-2861 1 N-stalker 1 N-stealth 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response header, which is directly injected into an HTML report.
CVE-2005-2859 1 Savant 1 Savant Webserver 2008-09-05 4.6 MEDIUM N/A
Savant Web Server stores user credentials in plaintext in the Savant\Users registry key, which allows local users to gain privileges.
CVE-2005-2858 1 Rediff 1 Bol 2008-09-05 5.0 MEDIUM N/A
The Fetch.FetchContact.1 ActiveX control (Fetch.dll) for Rediff Bol 7.0 allows remote attackers to read the Windows Address Book via the FullAddressBook method.
CVE-2005-2857 1 Softstack 1 Free Smtp Server 2008-09-05 7.5 HIGH N/A
Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy).
CVE-2005-2660 1 Apachetop 1 Apachetop 2008-09-05 2.1 LOW N/A
apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.
CVE-2005-2869 1 Phpmyadmin 1 Phpmyadmin 2008-09-05 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the Username to libraries/auth/cookie.auth.lib.php or (2) the error parameter to error.php.