Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 570

Количество 373 570

nvd логотип

CVE-2005-3653

больше 20 лет назад

Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2005-3652

больше 20 лет назад

Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-3651

больше 20 лет назад

Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrary code via crafted packets.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3650

больше 20 лет назад

The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2005-3649

больше 20 лет назад

jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-3648

больше 20 лет назад

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3647

больше 20 лет назад

Folder Guard allows local users to bypass protections by running from or installing to the temporary files directory.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-3646

больше 20 лет назад

Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3645

больше 20 лет назад

phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allows remote attackers to obtain the application installation path and other sensitive information via direct requests to (1) create.php, and if display_errors is enabled, (2) lib-updates.inc.php, (3) lib-targetstats.inc.php, (4) lib-size.inc.php, (5) lib-misc-stats.inc.php, (6) lib-hourly-hosts.inc.php, (7) lib-hourly.inc.php, (8) lib-history.inc.php, and (9) graph-daily.php.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-3644

больше 20 лет назад

PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.

CVSS2: 7.8
EPSS: Средний
nvd логотип

CVE-2005-3643

больше 20 лет назад

IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3642

больше 20 лет назад

IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3641

больше 20 лет назад

Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3640

больше 20 лет назад

Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to execute arbitrary code via long arguments to various IMAP commands, as demonstrated with the EXAMINE command.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2005-3639

больше 20 лет назад

PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-3638

больше 20 лет назад

Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in profile.php and (2) titles of posts.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3637

больше 20 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3530. Reason: This candidate is a duplicate of CVE-2005-3530. Notes: All CVE users should reference CVE-2005-3530 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2005-3636

больше 20 лет назад

Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3635

больше 20 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-3634

больше 20 лет назад

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-3653

Heap-based buffer overflow in the iGateway service for various Computer Associates (CA) iTechnology products, in iTechnology iGateway before 4.0.051230, allows remote attackers to execute arbitrary code via an HTTP request with a negative Content-Length field.

CVSS2: 10
19%
Средний
больше 20 лет назад
nvd логотип
CVE-2005-3652

Heap-based buffer overflow in Citrix Program Neighborhood client 9.0 and earlier allows remote attackers to execute arbitrary code via a long name value in an Application Set response.

CVSS2: 7.5
16%
Средний
больше 20 лет назад
nvd логотип
CVE-2005-3651

Stack-based buffer overflow in the dissect_ospf_v3_address_prefix function in the OSPF protocol dissector in Ethereal 0.10.12, and possibly other versions, allows remote attackers to execute arbitrary code via crafted packets.

CVSS2: 7.5
6%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3650

The CodeSupport.ocx ActiveX control, as used by Sony to uninstall the First4Internet XCP DRM, has "safe for scripting" enabled, which allows remote attackers to execute arbitrary code by calling vulnerable functions such as RebootMachine, IsAdministrator, and ExecuteCode.

CVSS2: 9.3
6%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3649

jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.

CVSS2: 2.6
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3648

Multiple SQL injection vulnerabilities in the get_record function in datalib.php in Moodle 1.5.2 allow remote attackers to execute arbitrary SQL commands via the id parameter in (1) category.php and (2) info.php.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3647

Folder Guard allows local users to bypass protections by running from or installing to the temporary files directory.

CVSS2: 4.6
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3646

Multiple SQL injection vulnerabilities in lib-sessions.inc.php in phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the sessionID parameter in (1) logout.php and (2) index.php.

CVSS2: 7.5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3645

phpAdsNew and phpPgAds 2.0.6 and possibly earlier versions allows remote attackers to obtain the application installation path and other sensitive information via direct requests to (1) create.php, and if display_errors is enabled, (2) lib-updates.inc.php, (3) lib-targetstats.inc.php, (4) lib-size.inc.php, (5) lib-misc-stats.inc.php, (6) lib-hourly-hosts.inc.php, (7) lib-hourly.inc.php, (8) lib-history.inc.php, and (9) graph-daily.php.

CVSS2: 5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3644

PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output buffer size, a variant of CVE-2006-6296, and a different vulnerability than CVE-2005-2120.

CVSS2: 7.8
42%
Средний
больше 20 лет назад
nvd логотип
CVE-2005-3643

IBM DB2 Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account without supplying a password.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3642

IBM Informix Dynamic Database server running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication and log on to the guest account by supplying an invalid username.

CVSS2: 7.5
1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3641

Oracle Databases running on Windows XP with Simple File Sharing enabled, allows remote attackers to bypass authentication by supplying a valid username.

CVSS2: 7.5
5%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3640

Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to execute arbitrary code via long arguments to various IMAP commands, as demonstrated with the EXAMINE command.

CVSS2: 10
9%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3639

PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.

CVSS2: 7.5
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3638

Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in profile.php and (2) titles of posts.

CVSS2: 4.3
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3637

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-3530. Reason: This candidate is a duplicate of CVE-2005-3530. Notes: All CVE users should reference CVE-2005-3530 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

больше 20 лет назад
nvd логотип
CVE-2005-3636

Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbitrary web script or HTML via Error Pages.

CVSS2: 4.3
5%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3635

Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote attackers to inject arbitrary web script or HTML via (1) the sap-syscmd in sap-syscmd and (2) the BspApplication field in the SYSTEM PUBLIC test application.

CVSS2: 4.3
5%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-3634

frameset.htm in the BSP runtime in SAP Web Application Server (WAS) 6.10 through 7.00 allows remote attackers to log users out and redirect them to arbitrary web sites via a close command in the sap-sessioncmd parameter and a URL in the sap-exiturl parameter.

CVSS2: 5
18%
Средний
больше 20 лет назад

Уязвимостей на страницу