Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 373 140

Количество 373 140

nvd логотип

CVE-2005-2980

почти 21 год назад

Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script or HTML via the rollid parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2979

почти 21 год назад

SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2978

почти 21 год назад

pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2977

почти 21 год назад

The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2976

больше 20 лет назад

Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2975

больше 20 лет назад

io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2005-2974

почти 21 год назад

libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-2973

почти 21 год назад

The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash).

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2972

почти 21 год назад

Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions in ie_imp_RTF.cpp, a different vulnerability than CVE-2005-2964.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2005-2971

почти 21 год назад

Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted RTF file.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2970

почти 21 год назад

Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2005-2969

почти 21 год назад

The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2968

почти 21 год назад

Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-2967

почти 21 год назад

Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in metadata in CDDB server responses when the victim plays a CD.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2966

почти 21 год назад

The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2005-2965

почти 21 год назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4802, CVE-2005-4803. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2005-4802 and CVE-2005-4803 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

EPSS: Низкий
nvd логотип

CVE-2005-2964

почти 21 год назад

Stack-based buffer overflow in AbiWord before 2.2.10 allows attackers to execute arbitrary code via the RTF import mechanism.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2963

почти 21 год назад

The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2962

почти 21 год назад

The post-installation script for ntlmaps before 0.9.9 sets world-readable permissions for the configuration file, which allows local users to obtain the username and password.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2961

почти 21 год назад

Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers to execute arbitrary code via a search response with a crafted string in the HREF field of an <A> tag.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2980

Cross-site scripting (XSS) vulnerability in index.php in phpoutsourcing Noah's classifieds 1.3 allows remote attackers to inject arbitrary web script or HTML via the rollid parameter.

CVSS2: 4.3
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2979

SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2978

pnmtopng in netpbm before 10.25, when using the -trans option, uses uninitialized size and index variables when converting Portable Anymap (PNM) images to Portable Network Graphics (PNG), which might allow attackers to execute arbitrary code by modifying the stack.

CVSS2: 7.5
5%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2977

The SELinux version of PAM before 0.78 r3 allows local users to perform brute force password guessing attacks via unix_chkpwd, which does not log failed guesses or delay its responses.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2976

Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186.

CVSS2: 7.5
5%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2975

io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors.

CVSS2: 7.8
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2974

libungif library before 4.1.0 allows attackers to cause a denial of service via a crafted GIF file that triggers a null dereference.

CVSS2: 2.6
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2973

The udp_v6_get_port function in udp.c in Linux 2.6 before 2.6.14-rc5, when running IPv6, allows local users to cause a denial of service (infinite loop and crash).

CVSS2: 2.1
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2972

Multiple stack-based buffer overflows in the RTF import feature in AbiWord before 2.2.11 allow user-assisted attackers to execute arbitrary code via an RTF file with long identifiers, which are not properly handled in the (1) ParseLevelText, (2) getCharsInsideBrace, (3) HandleLists, (4) or (5) HandleAbiLists functions in ie_imp_RTF.cpp, a different vulnerability than CVE-2005-2964.

CVSS2: 5.1
4%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2971

Heap-based buffer overflow in the KWord RTF importer for KOffice 1.2.0 through 1.4.1 allows remote attackers to execute arbitrary code via a crafted RTF file.

CVSS2: 7.5
6%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2970

Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections.

CVSS2: 5
14%
Средний
почти 21 год назад
nvd логотип
CVE-2005-2969

The SSL/TLS server implementation in OpenSSL 0.9.7 before 0.9.7h and 0.9.8 before 0.9.8a, when using the SSL_OP_MSIE_SSLV2_RSA_PADDING option, disables a verification step that is required for preventing protocol version rollback attacks, which allows remote attackers to force a client and server to use a weaker protocol than needed via a man-in-the-middle attack.

CVSS2: 5
5%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2968

Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash.

CVSS2: 7.5
11%
Средний
почти 21 год назад
nvd логотип
CVE-2005-2967

Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in metadata in CDDB server responses when the victim plays a CD.

CVSS2: 7.5
10%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2966

The Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted SVG file.

CVSS2: 5.1
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2965

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2005-4802, CVE-2005-4803. Reason: this candidate was intended for one issue, but the description and references inadvertently combined multiple issues. Notes: All CVE users should consult CVE-2005-4802 and CVE-2005-4803 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

почти 21 год назад
nvd логотип
CVE-2005-2964

Stack-based buffer overflow in AbiWord before 2.2.10 allows attackers to execute arbitrary code via the RTF import mechanism.

CVSS2: 7.5
5%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2963

The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions.

CVSS2: 7.5
2%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2962

The post-installation script for ntlmaps before 0.9.9 sets world-readable permissions for the configuration file, which allows local users to obtain the username and password.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-2961

Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers to execute arbitrary code via a search response with a crafted string in the HREF field of an <A> tag.

CVSS2: 7.5
9%
Низкий
почти 21 год назад

Уязвимостей на страницу