Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 374 083

Количество 374 083

nvd логотип

CVE-2005-4636

больше 20 лет назад

OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-4635

больше 20 лет назад

The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink messages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4634

больше 20 лет назад

SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information is unknown because the source URL is not available; the details are obtained solely from third party information.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4633

больше 20 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4619. Reason: This candidate is a duplicate of CVE-2005-4619. Notes: All CVE users should reference CVE-2005-4619 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2005-4632

больше 20 лет назад

SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4631

больше 20 лет назад

SQL injection vulnerability in index.php in Zina 0.12.07 and earlier allows remote attackers to execute arbitrary SQL commands via the p parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4630

больше 20 лет назад

SQL injection vulnerability in index.php in ClientExec 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) billshowid, (2) billdetailid, (3) fuse, and (4) frmClientID parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4629

больше 20 лет назад

SQL injection vulnerability in SMBCMS 2.1 allows remote attackers to execute arbitrary SQL commands via unspecified search parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4628

больше 20 лет назад

SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4627

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4626

больше 20 лет назад

The default configuration of Recruitment Software installs admin/site.xml under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (MySQL database credentials) via a direct request.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4625

больше 20 лет назад

Drivers for certain display adapters, including (1) an unspecified ATI driver and (2) an unspecified Intel driver, might allow remote attackers to cause a denial of service (system crash) via a large JPEG image, as demonstrated in Internet Explorer using stoopid.jpg with a width and height of 9999999.

CVSS2: 7.1
EPSS: Низкий
nvd логотип

CVE-2005-4624

больше 20 лет назад

The m_join function in channel.c for PTnet ircd 1.5 and 1.6 allows remote attackers to cause a denial of service (memory exhaustion that triggers a daemon restart) via a large number of requests to join a "charmed channel" such as PTnet, #PTnoticias and #*.log, which causes ircd to open the channel even though it does not have any valid users.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4623

больше 20 лет назад

upload.exe in eFileGo 3.01 allows remote attackers to cause a denial of service (CPU consumption) via an argument with an invalid directory name.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-4622

больше 20 лет назад

Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files via a ... (triple dot) in (1) the URL on port 608 and (2) the argument to upload.exe.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4621

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-4620

больше 20 лет назад

Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to specify a command-line argument for this program, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-4619

больше 20 лет назад

SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-4618

больше 20 лет назад

Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer. NOTE: since the sysctl is called from a userland program that provides the argument, this might not be a vulnerability, unless a legitimate user-assisted or setuid scenario can be identified.

CVSS2: 3.6
EPSS: Низкий
nvd логотип

CVE-2005-4617

больше 20 лет назад

SQL injection vulnerability in tickets.php in cSupport 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pg parameter.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-4636

OpenOffice.org 2.0 and earlier, when hyperlinks has been disabled, does not prevent the user from clicking the WWW-browser button in the Hyperlink dialog, which makes it easier for attackers to trick the user into bypassing intended security settings.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4635

The nl_fib_input function in fib_frontend.c in the Linux kernel before 2.6.15 does not check for valid lengths of the header and payload, which allows remote attackers to cause a denial of service (invalid memory reference) via malformed fib_lookup netlink messages.

CVSS2: 5
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4634

SQL injection vulnerability in index.php in ActiveCampaign SupportTrio 1.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the provenance of this information is unknown because the source URL is not available; the details are obtained solely from third party information.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4633

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4619. Reason: This candidate is a duplicate of CVE-2005-4619. Notes: All CVE users should reference CVE-2005-4619 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 20 лет назад
nvd логотип
CVE-2005-4632

SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4631

SQL injection vulnerability in index.php in Zina 0.12.07 and earlier allows remote attackers to execute arbitrary SQL commands via the p parameter.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4630

SQL injection vulnerability in index.php in ClientExec 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) billshowid, (2) billdetailid, (3) fuse, and (4) frmClientID parameters.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4629

SQL injection vulnerability in SMBCMS 2.1 allows remote attackers to execute arbitrary SQL commands via unspecified search parameters.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4628

SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4627

Cross-site scripting (XSS) vulnerability in index.php in (1) GmailSite 1.0 through 1.0.4 and (2) GFHost 0.1.1 through 0.4.2 allows remote attackers to inject arbitrary web script or HTML via the lng parameter.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4626

The default configuration of Recruitment Software installs admin/site.xml under the web document root with insufficient access control, which might allow remote attackers to obtain sensitive information (MySQL database credentials) via a direct request.

CVSS2: 5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4625

Drivers for certain display adapters, including (1) an unspecified ATI driver and (2) an unspecified Intel driver, might allow remote attackers to cause a denial of service (system crash) via a large JPEG image, as demonstrated in Internet Explorer using stoopid.jpg with a width and height of 9999999.

CVSS2: 7.1
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4624

The m_join function in channel.c for PTnet ircd 1.5 and 1.6 allows remote attackers to cause a denial of service (memory exhaustion that triggers a daemon restart) via a large number of requests to join a "charmed channel" such as PTnet, #PTnoticias and #*.log, which causes ircd to open the channel even though it does not have any valid users.

CVSS2: 5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4623

upload.exe in eFileGo 3.01 allows remote attackers to cause a denial of service (CPU consumption) via an argument with an invalid directory name.

CVSS2: 5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4622

Directory traversal vulnerability in eFileGo 3.01 allows remote attackers to execute arbitrary code, read arbitrary files, and upload arbitrary files via a ... (triple dot) in (1) the URL on port 608 and (2) the argument to upload.exe.

CVSS2: 7.5
4%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4621

Cross-site scripting (XSS) vulnerability in the editavatar page in vBulletin 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a URL in the remote avatar url field, in which the URL generates a parsing error, and possibly requiring a trailing extension such as .jpg.

CVSS2: 4.3
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4620

Buffer overflow in WinRAR 3.50 and earlier allows local users to execute arbitrary code via a long command-line argument. NOTE: because this program executes with the privileges of the invoking user, and because remote programs do not normally have the ability to specify a command-line argument for this program, there may not be a typical attack vector for the issue that crosses privilege boundaries. Therefore this may not be a vulnerability.

CVSS2: 4.6
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4619

SQL injection vulnerability in index.php in phpoutsourcing Zorum Forum 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the rollid parameter in the showhtmllist method.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4618

Buffer overflow in sysctl in the Linux Kernel 2.6 before 2.6.15 allows local users to corrupt user memory and possibly cause a denial of service via a long string, which causes sysctl to write a zero byte outside the buffer. NOTE: since the sysctl is called from a userland program that provides the argument, this might not be a vulnerability, unless a legitimate user-assisted or setuid scenario can be identified.

CVSS2: 3.6
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-4617

SQL injection vulnerability in tickets.php in cSupport 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pg parameter.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад

Уязвимостей на страницу