Search
Total
27796 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2005-2376 | 1 Codemasters | 1 Toca Race Driver | 2016-10-18 | 5.0 MEDIUM | N/A |
| Buffer overflow in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via a long (1) nickname or (2) chat message. | |||||
| CVE-2005-2299 | 1 Man And Machine Ltd. | 1 Simple Message Board | 2016-10-18 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Simple Message Board Version 2.0 Beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) FID parameter to forum.cfm, (2) UID parameter to user.cfm, (3) TID parameter to thread.cfm, or (4) PostDate parameter to search.cfm. | |||||
| CVE-2005-2291 | 1 Oracle | 1 Jdeveloper | 2016-10-18 | 4.6 MEDIUM | N/A |
| Oracle JDeveloper 9.0.4, 9.0.5, and 10.1.2 passes the cleartext password as a parameter when starting sqlplus, which allows local users to gain sensitive information. | |||||
| CVE-2005-2290 | 1 Wps | 1 Web Portal System | 2016-10-18 | 10.0 HIGH | N/A |
| wps_shop.cgi in WPS Web Portal System 0.7.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) art and (2) cat variables. | |||||
| CVE-2005-2289 | 1 Phpcounter | 1 Phpcounter | 2016-10-18 | 5.0 MEDIUM | N/A |
| PHPCounter 7.2 allows remote attackers to obtain sensitive information via a direct request to prelims.php, which reveals the path in an error message. | |||||
| CVE-2005-2390 | 1 Proftpd Project | 1 Proftpd | 2016-10-18 | 6.4 MEDIUM | N/A |
| Multiple format string vulnerabilities in ProFTPD before 1.3.0rc2 allow attackers to cause a denial of service or obtain sensitive information via (1) certain inputs to the shutdown message from ftpshut, or (2) the SQLShowInfo mod_sql directive. | |||||
| CVE-2005-2288 | 1 Phpcounter | 1 Phpcounter | 2016-10-18 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in PHPCounter 7.2 allows remote attackers to inject arbitrary web script or HTML via the EpochPrefix parameter. | |||||
| CVE-2005-2338 | 1 Xoops | 1 Xoops | 2016-10-18 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in the forum module. | |||||
| CVE-2005-2422 | 1 Beehive Forum | 1 Beehive Forum | 2016-10-18 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in index.php in Beehive Forum allows remote attackers to inject arbitrary web script or HTML via the webtag parameter. | |||||
| CVE-2005-2373 | 1 Whitsoft Development | 1 Slimftpd | 2016-10-18 | 7.2 HIGH | N/A |
| Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST, (2) DELE or (3) RNFR commands. | |||||
| CVE-2005-2381 | 1 Php Surveyor | 1 Php Surveyor | 2016-10-18 | 5.0 MEDIUM | N/A |
| PHP Surveyor 0.98 allows remote attackers to obtain sensitive information via a direct request to (1) question.php, (2) survey.php, or (3) group.php in the root directory, a direct request to (4) database.php, (5) sessioncontrol.php, (6) html.php, (7) sessioncontrol.php, an invalid (8) qid parameter to dumpquestion.php, or an invalid lid parameter to (9) labels.php or (10) dumplabel.php, which reveal the path in an error message. | |||||
| CVE-2005-2380 | 1 Php Surveyor | 1 Php Surveyor | 2016-10-18 | 5.0 MEDIUM | N/A |
| Multiple cross-site scripting vulnerabilities in PHP Surveyor 0.98 allow remote attackers to inject arbitrary web script or HTML via the (1) sid, (2) start, and (3) id parameters to browse.php, or the sid parameter to (4) dataentry.php or (5) export.php. | |||||
| CVE-2005-2372 | 1 Oracle | 1 Forms | 2016-10-18 | 7.2 HIGH | N/A |
| Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet. | |||||
| CVE-2005-2375 | 1 Codemasters | 1 Toca Race Driver | 2016-10-18 | 5.0 MEDIUM | N/A |
| Format string vulnerability in Race Driver 1.20 and earlier allows remote attackers to cause a denial of service (application crash) via format string specifiers in a (1) nickname or (2) chat message. | |||||
| CVE-2005-2301 | 1 Powerdns | 1 Powerdns | 2016-10-18 | 5.0 MEDIUM | N/A |
| PowerDNS before 2.9.18, when running with an LDAP backend, does not properly escape LDAP queries, which allows remote attackers to cause a denial of service (failure to answer ldap questions) and possibly conduct an LDAP injection attack. | |||||
| CVE-2005-2399 | 1 Php Surveyor | 1 Php Surveyor | 2016-10-18 | 7.5 HIGH | N/A |
| PHP Surveyor 0.98 allows remote attackers to trigger SQL errors via missing parameters to (1) browse.php, (2) export.php, (3) conditions.php, or (4) spss.php. | |||||
| CVE-2005-2302 | 1 Powerdns | 1 Powerdns | 2016-10-18 | 2.1 LOW | N/A |
| PowerDNS before 2.9.18, when allowing recursion to a restricted range of IP addresses, does not properly handle questions from clients that are denied recursion, which could cause a "blank out" of answers to those clients that are allowed to use recursion. | |||||
| CVE-2005-2300 | 1 Skype Technologies | 1 Skype | 2016-10-18 | 2.1 LOW | N/A |
| Skype 1.1.0.20 and earlier allows local users to overwrite arbitrary files via a symlink attack on the skype_profile.jpg temporary file. | |||||
| CVE-2005-2383 | 1 Phpnews | 1 Phpnews | 2016-10-18 | 7.5 HIGH | N/A |
| SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request. | |||||
| CVE-2005-2382 | 1 Oray | 1 Peanuthull | 2016-10-18 | 7.2 HIGH | N/A |
| Oray PeanutHull 3.0.1.0 and earlier does not properly drop SYSTEM privileges when launched from the system tray, which allows local users to gain privileges by accessing the Help functionality. | |||||
| CVE-2005-2195 | 1 Apple | 1 Darwin Streaming Server | 2016-10-18 | 5.0 MEDIUM | N/A |
| Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502. | |||||
| CVE-2005-2132 | 1 Sco | 1 Unixware | 2016-10-18 | 2.1 LOW | N/A |
| RPC portmapper (rpcbind) in SCO UnixWare 7.1.1 m5, 7.1.3 mp5, and 7.1.4 mp2 allows remote attackers or local users to cause a denial of service (lack of response) via multiple invalid portmap requests. | |||||
| CVE-2005-2257 | 1 Phpslash | 1 Phpslash | 2016-10-18 | 10.0 HIGH | N/A |
| The saveProfile function in PhpSlash 0.8.0 allows remote attackers to modify arbitrary profiles and gain privileges by modifying the author_id parameter. | |||||
| CVE-2005-2278 | 1 Mailenable | 1 Mailenable Professional | 2016-10-18 | 7.2 HIGH | N/A |
| Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name. | |||||
| CVE-2005-2287 | 1 Softiacom | 1 Wmailserver | 2016-10-18 | 5.0 MEDIUM | N/A |
| SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space, possibly triggering a buffer overflow. | |||||
| CVE-2005-2221 | 1 Incredible Interactive | 1 Dragonfly Commerce | 2016-10-18 | 7.5 HIGH | N/A |
| ** DISPUTED ** Multiple SQL injection vulnerabilities in Dragonfly Commerce allows remote attackers to modify SQL statements and possibly execute arbitrary SQL commands via the (1) key parameter to dc_Categoriesview.asp, (2) dc_productslist_Clearance.asp, (3) PID parameter to ratings.asp, (4) dc_Productsview.asp, (5) start, (6) key_mp, (7) searchtype, or (8) psearch parameters to dc_forum_Postslist.asp. NOTE: the vendor has disputed this issue, saying that the error messages arise from invalid category and product numbers. Assuming that this is the case, the issue still satisfies the CVE definition of "exposure." | |||||
| CVE-2005-2190 | 1 Comersus Open Technologies | 1 Comersus Cart | 2016-10-18 | 7.5 HIGH | N/A |
| Multiple SQL injection vulnerabilities in Comersus shopping cart allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to comersus_optAffiliateRegistrationExec.asp or (2) idProduct parameter to comersus_optReviewReadExec.asp. | |||||
| CVE-2005-2158 | 1 Jboss | 1 Jbpm | 2016-10-18 | 7.5 HIGH | N/A |
| A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identified by CVE-2003-0845. | |||||
| CVE-2005-2159 | 1 Planetdns | 1 Planetfileserver | 2016-10-18 | 5.0 MEDIUM | N/A |
| mshftp.dll in PlanetDNS PlanetFileServer 2.0.1.3 allows remote attackers to cause a denial of service (application crash) via a long request. | |||||
| CVE-2005-2160 | 1 Ipswitch | 1 Imail | 2016-10-18 | 5.0 MEDIUM | N/A |
| IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information. | |||||
| CVE-2005-2161 | 1 Phpbb Group | 1 Phpbb | 2016-10-18 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in phpBB 2.0.16 allows remote attackers to inject arbitrary web script or HTML via nested [url] tags. | |||||
| CVE-2005-2162 | 1 Levcgi.com | 1 Myguestbook | 2016-10-18 | 5.0 MEDIUM | N/A |
| PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter. | |||||
| CVE-2005-2163 | 1 Autoindex | 1 Php Script | 2016-10-18 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | |||||
| CVE-2005-2164 | 1 Covide Groupware-crm | 1 Covide | 2016-10-18 | 7.5 HIGH | N/A |
| SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. | |||||
| CVE-2005-2191 | 1 Comersus Open Technologies | 1 Comersus Cart | 2016-10-18 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp. | |||||
| CVE-2005-2178 | 1 Probe.cgi | 1 Probe.cgi | 2016-10-18 | 7.5 HIGH | N/A |
| probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter. NOTE: it is unclear which product or vendor this program is associated with, if any. | |||||
| CVE-2005-2179 | 1 Jaws | 1 Jaws | 2016-10-18 | 5.0 MEDIUM | N/A |
| PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter. | |||||
| CVE-2005-2180 | 1 Gnu | 1 Gnats | 2016-10-18 | 2.1 LOW | N/A |
| gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files. | |||||
| CVE-2005-2183 | 1 Phpxmail | 1 Phpxmail | 2016-10-18 | 7.5 HIGH | N/A |
| class.xmail.php in PhpXmail 0.7 through 1.1 does not properly handle large passwords, which prevents an error message from being returned and allows remote attackers to bypass authentication and gain unauthorized access. | |||||
| CVE-2005-2184 | 1 Emc | 1 Eroom | 2016-10-18 | 7.5 HIGH | N/A |
| eRoom 6.x does not properly restrict files that can be attached, which allows remote attackers to execute arbitrary commands via a .lnk file. | |||||
| CVE-2005-2185 | 1 Emc | 1 Eroom | 2016-10-18 | 7.5 HIGH | N/A |
| eRoom does not set an expiration for Cookies, which allows remote attackers to capture cookies and conduct replay attacks. | |||||
| CVE-2005-2186 | 1 Mcafee | 1 Intrushield Security Management System | 2016-10-18 | 1.9 LOW | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp. | |||||
| CVE-2005-2187 | 1 Mcafee | 1 Intrushield Security Management System | 2016-10-18 | 4.6 MEDIUM | N/A |
| McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp. | |||||
| CVE-2005-2188 | 1 Mcafee | 1 Intrushield Security Management System | 2016-10-18 | 7.5 HIGH | N/A |
| McAfee IntruShield Security Management System obtains the user ID from the URL, which allows remote attackers to guess the Manager account and possibly gain privileges via a brute force attack. | |||||
| CVE-2005-2189 | 1 Lantronix | 1 Securelinx | 2016-10-18 | 5.0 MEDIUM | N/A |
| Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys. | |||||
| CVE-2005-2197 | 1 Id Board | 1 Id Board | 2016-10-18 | 7.5 HIGH | N/A |
| SQL injection vulnerability in sql.cls.php in Id Board 1.1.3 allows remote attackers to modify SQL queries, as demonstrated using the f parameter to index.php. | |||||
| CVE-2005-2107 | 1 Wordpress | 1 Wordpress | 2016-10-18 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in post.php in WordPress 1.5.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) p or (2) comment parameter. | |||||
| CVE-2005-2108 | 1 Wordpress | 1 Wordpress | 2016-10-18 | 7.5 HIGH | N/A |
| SQL injection vulnerability in XMLRPC server in WordPress 1.5.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via input that is not filtered in the HTTP_RAW_POST_DATA variable, which stores the data in an XML file. | |||||
| CVE-2005-2109 | 1 Wordpress | 1 Wordpress | 2016-10-18 | 5.0 MEDIUM | N/A |
| wp-login.php in WordPress 1.5.1.2 and earlier allows remote attackers to change the content of the forgotten password e-mail message via the message variable, which is not initialized before use. | |||||
| CVE-2005-2192 | 1 Alexander Palmo | 1 Simple Php Blog | 2016-10-18 | 5.0 MEDIUM | N/A |
| SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack. | |||||
