Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-2198 1 Spid 1 Spid 2008-09-05 7.5 HIGH N/A
PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter.
CVE-2005-2508 1 Apple 2 Mac Os X, Mac Os X Server 2008-09-05 4.6 MEDIUM N/A
dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.
CVE-2005-2196 1 Apple 1 Airport Card 2008-09-05 2.1 LOW N/A
The Apple AirPort card uses a default WEP key when not connected to a known or trusted network, which can cause it to automatically connect to a malicious network.
CVE-2005-2507 1 Apple 1 Mac Os X Server 2008-09-05 7.5 HIGH N/A
Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
CVE-2005-2506 1 Apple 2 Mac Os X, Mac Os X Server 2008-09-05 5.0 MEDIUM N/A
Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.
CVE-2005-2486 1 Portailphp 1 Portailphp 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-2005-1701.
CVE-2005-2156 1 Phpnews 1 Phpnews 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter.
CVE-2005-2144 1 Prevx 1 Prevx Pro 2005 2008-09-05 2.1 LOW N/A
Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.
CVE-2005-2143 1 Microsoft 1 Frontpage 2008-09-05 5.0 MEDIUM N/A
Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.
CVE-2005-2391 1 3com 1 3crwe454g72 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in 3Com OfficeConnect Wireless 11g Access Point before 1.03.12 allows remote attackers to obtain sensitive information via the web interface.
CVE-2005-2393 1 Cutephp 1 Cutenews 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in CuteNews 1.3.6 allows remote attackers to inject arbitrary web script or HTML via (1) the lastusername parameter to index.php or (2) selected_search_arch parameter to search.php.
CVE-2005-2394 1 Cutephp 1 Cutenews 2008-09-05 5.0 MEDIUM N/A
show_news.php in CuteNews 1.3.6 allows remote attackers to obtain the full path of the server via an invalid archive parameter.
CVE-2005-2525 2 Apple, Easy Software Products 2 Mac Os X, Cups 2008-09-05 5.0 MEDIUM N/A
CUPS in Mac OS X 10.3.9 and 10.4.2 does not properly close file descriptors when handling multiple simultaneous print jobs, which allows remote attackers to cause a denial of service (printing halt).
CVE-2005-2258 1 Squitosoft 1 Squito Gallery 2008-09-05 7.5 HIGH N/A
PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter.
CVE-2005-2505 1 Apple 1 Mac Os X 2008-09-05 7.5 HIGH N/A
Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation.
CVE-2005-2515 1 Apple 1 Mac Os X 2008-09-05 4.6 MEDIUM N/A
Quartz Composer Screen Saver in Mac OS X 10.4.2 allows local users to access links from the RSS Visualizer even when a password is required.
CVE-2005-2253 1 Gianluca Baldo 1 Phpauction 2008-09-05 7.5 HIGH N/A
SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this description.
CVE-2005-2524 1 Apple 3 Mac Os X, Mac Os X Server, Safari 2008-09-05 5.0 MEDIUM N/A
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
CVE-2005-2526 2 Apple, Easy Software Products 2 Mac Os X, Cups 2008-09-05 5.0 MEDIUM N/A
CUPS in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to cause a denial of service (CPU consumption) by sending a partial IPP request and closing the connection.
CVE-2005-2259 1 Usanet Creations 6 Domain Name Auction, Makebid Auction Deluxe, Makebid Auction Standard and 3 more 2008-09-05 10.0 HIGH N/A
The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Software, and (4) MakeBid Reverse Auction allows remote attackers to execute arbitrary code via shell metacharacters in the DISPCLOSED parameter.
CVE-2005-2311 1 Sms 1 Sms 2008-09-05 2.1 LOW N/A
SMS 1.9.2m and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) request1 or (2) request2 temporary files.
CVE-2005-2328 1 Laffer 1 Laffer 2008-09-05 5.0 MEDIUM N/A
PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.
CVE-2005-2147 1 Edgewall Software 1 Trac 2008-09-05 6.4 MEDIUM N/A
Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.
CVE-2005-2255 1 Gianluca Baldo 1 Phpauction 2008-09-05 6.4 MEDIUM N/A
Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php.
CVE-2005-2146 1 Ssh 1 Tectia Server 2008-09-05 4.6 MEDIUM N/A
SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server.
CVE-2005-2256 1 Phppgadmin 1 Phppgadmin 2008-09-05 5.0 MEDIUM N/A
Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLanguage parameter.
CVE-2005-2329 1 Mrv Communications 3 In Reach Lx 1000s, In Reach Lx 4000s, In Reach Lx 8000s 2008-09-05 4.6 MEDIUM N/A
MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to access the consoles of other users.
CVE-2005-2332 1 Php.warpedweb.net 1 Phppageprotect 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a allows remote attackers to inject arbitrary web script or HTML via the username parameter to (1) admin.php or (2) login.php.
CVE-2005-2222 1 Mailenable 1 Mailenable Professional 2008-09-05 10.0 HIGH N/A
Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.
CVE-2005-2385 1 Alwil 1 Avast Antivirus 2008-09-05 7.5 HIGH N/A
Buffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to execute arbitrary code via an ACE archive containing a long filename.
CVE-2005-2205 1 Pngren 1 Pngren 2008-09-05 7.5 HIGH N/A
The ReadLog function in kaiseki.cgi in pngren allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.
CVE-2005-2513 1 Apple 1 Mac Os X 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in HItoolbox for Mac OS X 10.4.2 allows VoiceOver services to read secure input fields.
CVE-2005-2203 1 Phpwishlist 1 Phpwishlist 2008-09-05 7.5 HIGH N/A
login.php in phpWishlist before 0.1.15 allows remote attackers to bypass authentication via a direct request to admin.php.
CVE-2005-2386 1 Elemental Software 1 Cartwiz 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
CVE-2005-2202 1 Xerox 3 Workcentre 2128, Workcentre 2636, Workcentre 3545 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
CVE-2005-2387 1 Goodtech Systems 1 Goodtech Smtp Server 2008-09-05 7.5 HIGH N/A
Multiple stack-based buffer overflows in GoodTech SMTP server 5.16 allow remote attackers to execute arbitrary code via (1) a RCPT TO command with a long DNS name, or (2) a large number of RCPT TO commands with a long e-mail name arugment in the last command.
CVE-2005-2201 1 Xerox 3 Workcentre 2128, Workcentre 2636, Workcentre 3545 2008-09-05 6.4 MEDIUM N/A
Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.
CVE-2005-2167 1 Frozenplague.net 1 Plague News System 2008-09-05 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the cid parameter.
CVE-2005-2389 1 Symantec Veritas 2 Netbackup Enterprise Server, Netbackup Server 2008-09-05 5.0 MEDIUM N/A
NDMP server in Veritas NetBackup 5.1 allows attackers to cause a denial of service via a CONFIG message with an out-of-range timestamp, which triggers a null dereference.
CVE-2005-2226 1 Microsoft 1 Outlook Express 2008-09-05 5.0 MEDIUM N/A
Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information.
CVE-2005-2166 1 Frozenplague.net 1 Plague News System 2008-09-05 5.0 MEDIUM N/A
SQL injection vulnerability in index.php in Plague News System 0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
CVE-2005-2249 1 Jinzora 1 Jinzora 2008-09-05 10.0 HIGH N/A
Multiple unknown vulnerabilities in Jinzora 2.0.1 have unknown impact and attack vectors, possibly involving a PHP file inclusion vulnerability.
CVE-2005-2165 1 Globalnotescript 1 Globalnotescript 2008-09-05 7.5 HIGH N/A
read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.
CVE-2005-2250 1 Nokia 1 Affix 2008-09-05 7.5 HIGH N/A
Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.
CVE-2005-2151 1 Double Precision Incorporated 1 Courier Mail Server 2008-09-05 5.0 MEDIUM N/A
spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption.
CVE-2005-2223 1 Mailenable 2 Mailenable Professional, Mailenable Standard 2008-09-05 5.0 MEDIUM N/A
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.
CVE-2005-2252 1 Gianluca Baldo 1 Phpauction 2008-09-05 7.5 HIGH N/A
PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.
CVE-2005-2514 1 Apple 1 Mac Os X 2008-09-05 7.5 HIGH N/A
Buffer overflow in ping in Mac OS X 10.3.9 allows local users to execute arbitrary code.
CVE-2005-2512 1 Apple 2 Mac Os X, Mail 2008-09-05 2.1 LOW N/A
Mail.app in Mac OS 10.4.2 and earlier, when printing or forwarding an HTML message, loads remote images even when the user's preferences state otherwise, which could result in a privacy leak.
CVE-2005-1933 1 Apple 1 Mac Os X 2008-09-05 7.5 HIGH N/A
Dashboard in Apple Mac OS X Tiger 10.4 allows attackers to execute arbitrary commands by overriding the behavior of system widgets via a user widget with the same bundle identifier (CFBundleIdentifier), a different vulnerability than CVE-2005-1474.