Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 878

Количество 331 878

nvd логотип

CVE-2005-1899

больше 20 лет назад

Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1898

больше 20 лет назад

The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1897

больше 20 лет назад

Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2005-1896

больше 20 лет назад

Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation path via the image parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1895

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1894

больше 20 лет назад

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1893

больше 20 лет назад

FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1892

больше 20 лет назад

FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-1891

больше 20 лет назад

The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1890

больше 20 лет назад

Unknown vulnerability in Mortiforo before 0.9.1 allows users to access private forums via unknown attack vectors.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1889

больше 20 лет назад

Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1888

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1887

больше 20 лет назад

Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-1886

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1885

больше 20 лет назад

view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to obtain sensitive information via a phid parameter that is not an integer, which reveals the path in an error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1884

больше 20 лет назад

Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-1883

больше 20 лет назад

global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1882

больше 20 лет назад

PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1881

больше 20 лет назад

upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1880

больше 20 лет назад

everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-1899

Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products including nFusion Elite Warriors: Vietnam, allows remote attackers to cause a denial of service (infinite loop) via a zero-byte UDP packet.

CVSS2: 5
5%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1898

The passthrough functionality in phpThumb.php in phpThumb() before 1.5.4 allows remote attackers to read files that are not images.

CVSS2: 5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1897

Unknown vulnerability in FlexCast Audio Video Streaming Server before 2.0 has unknown impact and attack vectors.

CVSS2: 10
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1896

Directory traversal vulnerability in thumb.php in FlatNuke 2.5.3 allows remote attackers to read arbitrary images or obtain the installation path via the image parameter.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1895

Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTML via the border or back parameters to (1) help.php or (2) footer.php.

CVSS2: 4.3
4%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1894

Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which causes the code to be injected into referer.php, which can then be accessed by the attacker.

CVSS2: 7.5
9%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1893

FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.

CVSS2: 5
7%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1892

FlatNuke 2.5.3 allows remote attackers to cause a denial of service or obtain sensitive information via (1) a direct request to foot_news.php, which triggers an infinite loop, or (2) direct requests to unknown scripts, which reveals the web document root in an error message.

CVSS2: 6.4
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1891

The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.

CVSS3: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1890

Unknown vulnerability in Mortiforo before 0.9.1 allows users to access private forums via unknown attack vectors.

CVSS2: 5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1889

Unknown vulnerability in Sun ONE Application Server 6.5 SP1 Maintenance Update 6 and earlier allows attackers to read files.

CVSS2: 5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1888

Cross-site scripting (XSS) vulnerability in MediaWiki before 1.4.5 allows remote attackers to inject arbitrary web script via HTML attributes in page templates.

CVSS2: 4.3
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1887

Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1886

Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2) unknown parameters when posting a new comment.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1885

view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to obtain sensitive information via a phid parameter that is not an integer, which reveals the path in an error message.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1884

Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directories via a .. (dot dot) in the dir parameter.

CVSS2: 6.4
4%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1883

global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1882

PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1881

upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code.

CVSS2: 7.5
7%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1880

everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.

CVSS3: 5.5
0%
Низкий
больше 20 лет назад

Уязвимостей на страницу