Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 855

Количество 372 855

nvd логотип

CVE-2005-2083

около 21 года назад

Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2082

около 21 года назад

im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2081

около 21 года назад

Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2080

около 21 года назад

Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2079

около 21 года назад

Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2078

около 21 года назад

BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2077

около 21 года назад

Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2076

около 21 года назад

HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2075

около 21 года назад

PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2074

около 21 года назад

Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.0.105 allows remote attackers to inject arbitrary web script or HTML via a news or article post, possibly involving the (1) news_body, (2) article_description, or (3) article_body parameters to submit.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-2073

около 21 года назад

Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-2072

около 21 года назад

The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-2071

около 21 года назад

traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-2070

около 21 года назад

The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2069

около 21 года назад

pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2068

около 21 года назад

FreeBSD 4.x through 4.11 and 5.x through 5.4 allows remote attackers to modify certain TCP options via a TCP packet with the SYN flag set for an already established session.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2067

около 21 года назад

SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2066

около 21 года назад

SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2065

около 21 года назад

HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2064

около 21 года назад

Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-2083

Format string vulnerability in IMAP4 in IA eMailServer Corporate Edition 5.2.2 build 1051 allows remote attackers to cause a denial of service (application crash) via a LIST command with format string specifiers as the second argument.

CVSS2: 5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2082

im_trbbs.cgi in imTRSET 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the df parameter.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2081

Stack-based buffer overflow in the function that parses commands in Asterisk 1.0.7, when the 'write = command' option is enabled, allows remote attackers to execute arbitrary code via a command that has two double quotes followed by a tab character.

CVSS2: 5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2080

Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2079

Heap-based buffer overflow in the Admin Plus Pack Option for VERITAS Backup Exec 9.0 through 10.0 for Windows Servers allows remote attackers to execute arbitrary code.

CVSS2: 7.5
5%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2078

BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.

CVSS2: 2.1
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2077

Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.

CVSS2: 4.3
4%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2076

HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.

CVSS2: 2.1
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2075

PHP-Fusion 5.0 and 6.0 stores the database file with a predictable filename under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to the filename in the administration/db_backups directory in PHP-Fusion 6.0 or the fusion_admin/db_backups directory in 5.0.

CVSS2: 5
7%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2074

Cross-site scripting (XSS) vulnerability in PHP-Fusion 6.0.105 allows remote attackers to inject arbitrary web script or HTML via a news or article post, possibly involving the (1) news_body, (2) article_description, or (3) article_body parameters to submit.php.

CVSS2: 4.3
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2073

Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2072

The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.

CVSS2: 7.2
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2071

traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).

CVSS2: 4.6
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2070

The ClamAV Mail fILTER (clamav-milter) 0.84 through 0.85d, when used in Sendmail using long timeouts, allows remote attackers to cause a denial of service by keeping an open connection, which prevents ClamAV from reloading.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2069

pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.

CVSS2: 5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2068

FreeBSD 4.x through 4.11 and 5.x through 5.4 allows remote attackers to modify certain TCP options via a TCP packet with the SYN flag set for an already established session.

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2067

SQL injection vulnerability in article.asp in unknown versions of aspnuke allows remote attackers to execute arbitrary SQL commands via the articleid parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2066

SQL injection vulnerability in comment_post.asp in ASP Nuke 0.80 allows remote attackers to execute arbitrary SQL statements via the TaskID parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2065

HTTP response splitting vulnerability in language_select.asp in ASP Nuke 0.80 allows remote attackers to spoof web content and poison web caches via CRLF ("%0d%0a") sequences in the LangCode parameter.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-2064

Multiple cross-site scripting vulnerabilities in ASP Nuke 0.80 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to forgot_password.asp, or the (2) FirstName, (3) LastName, (4) Username, (5) Password, (6) Address1, (7) Address2, (8) City, (9) ZipCode, (10) Email parameter to register.asp.

CVSS2: 5
2%
Низкий
около 21 года назад

Уязвимостей на страницу