Логотип exploitDog
source:"nvd"
Консоль
Логотип exploitDog

exploitDog

source:"nvd"

Количество 331 703

Количество 331 703

nvd логотип

CVE-2005-1410

почти 21 год назад

The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-1409

почти 21 год назад

PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1408

больше 20 лет назад

Apple Keynote 2.0 and 2.0.1 allows remote attackers to read arbitrary files via the keynote: URI handler in a crafted Keynote presentation.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1407

почти 21 год назад

Skype for Windows 1.2.0.0 to 1.2.0.46 allows local users to bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-1406

почти 21 год назад

The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-1405

почти 21 год назад

HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-1404

почти 21 год назад

MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1403

почти 21 год назад

Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2005-1402

почти 21 год назад

Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1401

почти 21 год назад

Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-1400

почти 21 год назад

The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-1399

почти 21 год назад

FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-1398

почти 21 год назад

phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 through 4.6.4 are also affected.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2005-1397

почти 21 год назад

SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1396

почти 21 год назад

Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2005-1395

почти 21 год назад

Buffer overflow in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier may allow local users to gain privileges via a long (1) XAPPLRESLANGPATH or (2) XAPPLRESDIR environment variable, or (3) command line argument.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-1394

почти 21 год назад

Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-1393

почти 21 год назад

Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-1392

почти 21 год назад

The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-1391

почти 21 год назад

Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP header.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-1410

The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1409

PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1408

Apple Keynote 2.0 and 2.0.1 allows remote attackers to read arbitrary files via the keynote: URI handler in a crafted Keynote presentation.

CVSS2: 5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-1407

Skype for Windows 1.2.0.0 to 1.2.0.46 allows local users to bypass the identity check for an authorized application, then call arbitrary Skype API functions by modifying or replacing that application.

CVSS2: 4.6
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1406

The kernel in FreeBSD 4.x to 4.11 and 5.x to 5.4 does not properly clear certain fixed-length buffers when copying variable-length data for use by applications, which could allow those applications to read previously used sensitive memory.

CVSS2: 4.6
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1405

HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1404

MyPHP Forum 1.0 allows remote attackers to spoof the username by modifying the (1) nbuser parameter to post.php or (2) sender parameter to privmsg.php.

CVSS2: 5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1403

Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to inject arbitrary web script or HTML via the (1) image parameter to closeup.php, the (2) currentIsExpanded or (3) searchFor parameters to index.php, (4) the currentNumber parameter to software_CAD_Technical_60002_uk.htm, or (5) a cookie.

CVSS2: 6.8
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1402

Integer signedness error in certain older versions of the NeL library, as used in Mtp-Target 1.2.2 and earlier, and possibly other products, allows remote attackers to cause a denial of service (memory consumption or server crash) via a negative value in a STLport call, which is not caught by a signed comparison.

CVSS2: 5
6%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1401

Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.

CVSS2: 7.5
13%
Средний
почти 21 год назад
nvd логотип
CVE-2005-1400

The i386_get_ldt system call in FreeBSD 4.7 to 4.11 and 5.x to 5.4 allows local users to access sensitive kernel memory via arguments with negative or very large values.

CVSS2: 4.6
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1399

FreeBSD 4.6 to 4.11 and 5.x to 5.4 uses insecure default permissions for the /dev/iir device, which allows local users to execute restricted ioctl calls to read or modify data on hardware that is controlled by the iir driver.

CVSS2: 4.6
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1398

phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2) postage parameters. NOTE: it was later reported that 3.4 through 4.6.4 are also affected.

CVSS2: 5
11%
Средний
почти 21 год назад
nvd логотип
CVE-2005-1397

SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

CVSS2: 7.5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1396

Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.

CVSS2: 1.2
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1395

Buffer overflow in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier may allow local users to gain privileges via a long (1) XAPPLRESLANGPATH or (2) XAPPLRESDIR environment variable, or (3) command line argument.

CVSS2: 7.2
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1394

Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.

CVSS2: 7.2
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1393

Multiple buffer overflows in ArcGIS for ESRI ArcInfo Workstation 9.0 allow local users to execute arbitrary code via long command line arguments to (1) asmaster, (2) asuser, (3) asutility, (4) se, or (5) asrecovery.

CVSS2: 4.6
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1392

The SQL install script in phpMyAdmin 2.6.2 is created with world-readable permissions, which allows local users to obtain the initial database password by reading the script.

CVSS2: 4.6
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-1391

Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host HTTP header.

CVSS2: 7.5
8%
Низкий
почти 21 год назад

Уязвимостей на страницу