|
357401
|
7.2 |
HIGH
|
ibm
|
aix
|
Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.
|
NVD-CWE-Other
|
CVE-2005-2236
|
2008-09-6 05:51 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357402
|
7.2 |
HIGH
|
-
|
-
|
Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.
|
NVD-CWE-Other
|
CVE-2005-2237
|
2008-09-6 05:51 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357403
|
2.1 |
LOW
|
ibm
|
aix
|
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
|
NVD-CWE-Other
|
CVE-2005-2238
|
2008-09-6 05:51 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357404
|
5.0 |
MEDIUM
|
oftpd
|
oftpd
|
oftpd 0.3.7 allows remote attackers to cause a denial of service via a USER command with a large number of null (\0) characters.
|
NVD-CWE-Other
|
CVE-2005-2239
|
2008-09-6 05:51 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357405
|
2.1 |
LOW
|
xpvm
|
xpvm
|
xpvm.tcl in xpvm 1.2.5 allows local users to overwrite arbitrary files via a symlink attack on the xpvm.trace.$user temporary file.
|
NVD-CWE-Other
|
CVE-2005-2240
|
2008-09-6 05:51 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357406
|
5.0 |
MEDIUM
|
cisco
|
call_manager
|
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 does not quickly time out Realtime Information Server Data Collection (RISDC) sockets,…
|
NVD-CWE-Other
|
CVE-2005-2241
|
2008-09-6 05:51 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357407
|
5.0 |
MEDIUM
|
-
|
-
|
Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1 allows remote attackers to cause a denial of service (memory consumption and restart) …
|
NVD-CWE-Other
|
CVE-2005-2242
|
2008-09-6 05:51 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357408
|
5.0 |
MEDIUM
|
cisco
|
call_manager
|
Memory leak in inetinfo.exe in Cisco CallManager (CCM) 3.2 and earlier, 3.3 before 3.3(5), 4.0 before 4.0(2a)SR2b, and 4.1 4.1 before 4.1(3)SR1, when Multi Level Admin (MLA) is enabled, allows remote…
|
NVD-CWE-Other
|
CVE-2005-2243
|
2008-09-6 05:51 |
2005-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357409
|
5.0 |
MEDIUM
|
sven-ove_bjerkan
|
downloadprotect
|
Directory traversal vulnerability in DownloadProtect before 1.0.3 allows remote attackers to read files above the download folder.
|
NVD-CWE-Other
|
CVE-2005-2248
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357410
|
10.0 |
HIGH
|
jinzora
|
jinzora
|
Multiple unknown vulnerabilities in Jinzora 2.0.1 have unknown impact and attack vectors, possibly involving a PHP file inclusion vulnerability.
|
NVD-CWE-Other
|
CVE-2005-2249
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357411
|
7.5 |
HIGH
|
nokia
|
affix
|
Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.
|
NVD-CWE-Other
|
CVE-2005-2250
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357412
|
7.5 |
HIGH
|
gianluca_baldo
|
phpauction
|
PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID.
|
NVD-CWE-Other
|
CVE-2005-2252
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357413
|
7.5 |
HIGH
|
gianluca_baldo
|
phpauction
|
SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the…
|
NVD-CWE-Other
|
CVE-2005-2253
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357414
|
6.4 |
MEDIUM
|
gianluca_baldo
|
phpauction
|
Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan param…
|
NVD-CWE-Other
|
CVE-2005-2255
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357415
|
5.0 |
MEDIUM
|
phppgadmin
|
phppgadmin
|
Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLanguage parameter.
|
NVD-CWE-Other
|
CVE-2005-2256
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357416
|
7.5 |
HIGH
|
squitosoft
|
squito_gallery
|
PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter.
|
NVD-CWE-Other
|
CVE-2005-2258
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357417
|
10.0 |
HIGH
|
usanet_creations
|
domain_name_auction makebid_auction_deluxe makebid_auction_standard makebid_reverse_auction standard_classified_ads usanet_shopping_mall
|
The dispallclosed2 function in dispallclosed.pl for multiple USANet Creations products, including (1) USANet Shopping Mall Software, (2) Domain Name Auction Software, (3) Standard Classified Ads Soft…
|
NVD-CWE-Other
|
CVE-2005-2259
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357418
|
2.6 |
LOW
|
alexander_clauss
|
icab
|
iCab 2.9.8 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing att…
|
NVD-CWE-Other
|
CVE-2005-2271
|
2008-09-6 05:51 |
2005-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357419
|
4.3 |
MEDIUM
|
esi_products
|
webeoc
|
Multiple cross-site scripting (XSS) vulnerabilities in WebEOC before 6.0.2 allow remote attackers to inject arbitrary web script and HTML via unknown vectors.
|
NVD-CWE-Other
|
CVE-2005-2282
|
2008-09-6 05:51 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357420
|
2.1 |
LOW
|
esi_products
|
webeoc
|
WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a larg…
|
NVD-CWE-Other
|
CVE-2005-2283
|
2008-09-6 05:51 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357421
|
7.5 |
HIGH
|
esi_products
|
webeoc
|
Multiple SQL injection vulnerabilities in WebEOC before 6.0.2 allow remote attackers to modify SQL statements via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-2284
|
2008-09-6 05:51 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357422
|
5.0 |
MEDIUM
|
esi_products
|
webeoc
|
WebEOC before 6.0.2 stores sensitive information in locations such as URIs, web pages, and configuration files, which allows remote attackers to obtain information such as Usernames, Passwords, Emerg…
|
NVD-CWE-Other
|
CVE-2005-2285
|
2008-09-6 05:51 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357423
|
10.0 |
HIGH
|
esi_products
|
webeoc
|
WebEOC before 6.0.2 does not properly check user authorization, which allows remote attackers to gain privileges via a direct request to a resource.
|
NVD-CWE-Other
|
CVE-2005-2286
|
2008-09-6 05:51 |
2005-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357424
|
7.5 |
HIGH
|
dg
|
remote_control_server
|
DG Remote Control Server 1.6.2 allows remote attackers to cause a denial of service (crash or CPU consumption) and possibly execute arbitrary code via a long message to TCP port 1071 or 1073, possibl…
|
NVD-CWE-Other
|
CVE-2005-2305
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357425
|
3.7 |
LOW
|
macromedia
|
coldfusion jrun
|
Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated u…
|
NVD-CWE-Other
|
CVE-2005-2306
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357426
|
7.5 |
HIGH
|
microsoft
|
ie
|
The JPEG decoder in Microsoft Internet Explorer allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitrary code via certain crafted JPEG images, as…
|
NVD-CWE-Other
|
CVE-2005-2308
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357427
|
2.1 |
LOW
|
sms
|
sms
|
SMS 1.9.2m and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) request1 or (2) request2 temporary files.
|
NVD-CWE-Other
|
CVE-2005-2311
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357428
|
7.5 |
HIGH
|
realnode
|
emilda
|
management.php in Realnode Emilda 1.2.2 and earlier allows remote attackers to perform actions as other users by modifying the user_id parameter.
|
NVD-CWE-Other
|
CVE-2005-2312
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357429
|
7.2 |
HIGH
|
-
|
-
|
Check Point SecuRemote NG with Application Intelligence R54 allows attackers to obtain credentials and gain privileges via unknown attack vectors.
|
NVD-CWE-Other
|
CVE-2005-2313
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357430
|
7.5 |
HIGH
|
dnrd
|
dnrd
|
Buffer overflow in Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to execute arbitrary code via a large number of large DNS packets with the Z and QR flags cleared.
|
NVD-CWE-Other
|
CVE-2005-2315
|
2008-09-6 05:51 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357431
|
7.5 |
HIGH
|
dnrd
|
dnrd
|
This vulnerability is addressed in the following product release:
dnrd, dnrd, 2.19.1
This vulnerability affects all versions of dnrd prior to 2.19.1
|
NVD-CWE-Other
|
CVE-2005-2315
|
2008-09-6 05:51 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357432
|
5.0 |
MEDIUM
|
dnrd
|
dnrd
|
Domain Name Relay Daemon (DNRD) before 2.19.1 allows remote attackers to cause a denial of service (infinite recursion) via a DNS packet that uses message compression in the QNAME and two pointers th…
|
NVD-CWE-Other
|
CVE-2005-2316
|
2008-09-6 05:51 |
2005-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357433
|
7.5 |
HIGH
|
shorewall
|
shorewall
|
Shorewall 2.4.x before 2.4.1, 2.2.x before 2.2.5, and 2.0.x before 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with an accepted MAC add…
|
NVD-CWE-Other
|
CVE-2005-2317
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357434
|
4.3 |
MEDIUM
|
dvbbs
|
dvbbs
|
Cross-site scripting (XSS) vulnerability in showerr.asp in DVBBS 7.1 SP2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
|
NVD-CWE-Other
|
CVE-2005-2318
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357435
|
5.0 |
MEDIUM
|
yawp
|
yawp
|
PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] par…
|
NVD-CWE-Other
|
CVE-2005-2319
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357436
|
7.5 |
HIGH
|
webcalendar
|
webcalendar
|
WebCalendar before 1.0.0 does not properly restrict access to assistant_edit.php, which allows remote attackers to gain privileges.
|
NVD-CWE-Other
|
CVE-2005-2320
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357437
|
4.3 |
MEDIUM
|
class-1 clever_copy
|
class-1_forum clever_copy
|
Cross-site scripting (XSS) vulnerability in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allows remote attackers to inject arbitrary web script or HTML via the (1) viewuser…
|
NVD-CWE-Other
|
CVE-2005-2322
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357438
|
7.5 |
HIGH
|
class-1 clever_copy
|
class-1_forum clever_copy
|
Multiple SQL injection vulnerabilities in Class-1 Forum 0.24.4 and 0.23.2, and Clever Copy with forums installed, allow remote attackers to modify SQL statements via the (1) id parameter to viewattac…
|
NVD-CWE-Other
|
CVE-2005-2323
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357439
|
4.3 |
MEDIUM
|
clever_copy
|
clever_copy
|
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the searchtype or searchterm parameters to (1) results.php or (…
|
NVD-CWE-Other
|
CVE-2005-2324
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357440
|
5.0 |
MEDIUM
|
clever_copy
|
clever_copy
|
Clever Copy 2.0 and 2.0a allows remote attackers to obtain the full path of the web root via a direct request to (1) ticker.php, (2) menu.php, (3) banned.php, (4) endlayout.php, (5) randomhlinesblock…
|
NVD-CWE-Other
|
CVE-2005-2325
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357441
|
4.3 |
MEDIUM
|
clever_copy
|
clever_copy
|
Cross-site scripting (XSS) vulnerability in Clever Copy 2.0 and 2.0a allows remote attackers to inject arbitrary web script or HTML via the yr parameter to calendar.php.
|
NVD-CWE-Other
|
CVE-2005-2326
|
2008-09-6 05:51 |
2005-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357442
|
5.0 |
MEDIUM
|
laffer
|
laffer
|
PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable.
|
NVD-CWE-Other
|
CVE-2005-2328
|
2008-09-6 05:51 |
2005-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357443
|
4.6 |
MEDIUM
|
-
|
-
|
MRV Communications In-Reach LX-8000S, LX-4000S, and LX-1000S 3.5.0, when using SSH public key authentication, does not properly restrict access to ports, which allows remote authenticated users to ac…
|
NVD-CWE-Other
|
CVE-2005-2329
|
2008-09-6 05:51 |
2005-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357444
|
4.3 |
MEDIUM
|
php.warpedweb.net
|
phppageprotect
|
Cross-site scripting (XSS) vulnerability in PHPPageProtect 1.0.0a allows remote attackers to inject arbitrary web script or HTML via the username parameter to (1) admin.php or (2) login.php.
|
NVD-CWE-Other
|
CVE-2005-2332
|
2008-09-6 05:51 |
2005-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357445
|
10.0 |
HIGH
|
y.sak
|
y.sak
|
Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.
|
NVD-CWE-Other
|
CVE-2005-2334
|
2008-09-6 05:51 |
2005-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357446
|
4.3 |
MEDIUM
|
msearch
|
unicode_msearch
|
Cross-site scripting (XSS) vulnerability in the Unicode version of msearch (unicode-msearch) 1.51(U1)-beta1, 1.51(U1), and 1.52(U1) allows remote attackers to inject arbitrary web script or HTML via …
|
NVD-CWE-Other
|
CVE-2005-2339
|
2008-09-6 05:51 |
2005-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357447
|
5.0 |
MEDIUM
|
emc
|
navisphere_manager
|
EMC Navisphere Manager 6.4.1.0.0 allows remote attackers to list arbitrary directories via an HTTP request for a directory that ends in a "." (trailing dot).
|
NVD-CWE-Other
|
CVE-2005-2358
|
2008-09-6 05:51 |
2005-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357448
|
5.0 |
MEDIUM
|
alwil
|
avast_antivirus
|
Directory traversal vulnerability in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers…
|
NVD-CWE-Other
|
CVE-2005-2384
|
2008-09-6 05:51 |
2005-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357449
|
7.5 |
HIGH
|
alwil
|
avast_antivirus
|
Buffer overflow in a third-party compression library (UNACEV2.DLL), as used in avast! Antivirus Home/Professional Edition 4.6.665 and Server Edition 4.6.460, allows remote attackers to execute arbitr…
|
NVD-CWE-Other
|
CVE-2005-2385
|
2008-09-6 05:51 |
2005-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357450
|
4.3 |
MEDIUM
|
elemental_software
|
cartwiz
|
Cross-site scripting (XSS) vulnerability in viewCart.asp in CartWIZ 1.20 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
|
NVD-CWE-Other
|
CVE-2005-2386
|
2008-09-6 05:51 |
2005-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|