Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 855

Количество 372 855

nvd логотип

CVE-2005-1795

около 21 года назад

The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent the file from being deleted and ditto is invoked.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1794

около 21 года назад

Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.

CVSS2: 6.4
EPSS: Средний
nvd логотип

CVE-2005-1793

около 21 года назад

User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-1792

около 21 года назад

Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1791

около 21 года назад

Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address. NOTE: if there is not an exploit scenario in which an attacker can trigger this behavior, then perhaps this issue should not be included in CVE.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-1790

около 21 года назад

Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."

CVSS2: 2.6
EPSS: Высокий
nvd логотип

CVE-2005-1789

около 21 года назад

SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1788

около 21 года назад

SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1787

около 21 года назад

setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-1786

около 21 года назад

SQL injection vulnerability in admin.asp in FunkyASP AD System 1.1 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1785

около 21 года назад

SQL injection vulnerability in ad/login.asp in ZonGG 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1784

около 21 года назад

Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1783

около 21 года назад

BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the resulting error message. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1782

около 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1781

около 21 года назад

Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1780

около 21 года назад

SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1779

около 21 года назад

SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1778

около 21 года назад

Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-1777

около 21 года назад

SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1776

около 21 года назад

Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C'Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-1795

The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent the file from being deleted and ditto is invoked.

CVSS2: 7.5
4%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1794

Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.

CVSS2: 6.4
16%
Средний
около 21 года назад
nvd логотип
CVE-2005-1793

User32.DLL in Microsoft Windows 98SE, and possibly other operating systems, allows local and remote attackers to cause a denial of service (crash) via an icon (.ico) bitmap file with large width and height values.

CVSS2: 2.6
7%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1792

Memory leak in Windows Management Instrumentation (WMI) service allows attackers to cause a denial of service (memory consumption and crash) by creating security contexts more quickly than they can be cleared from the RPC cache.

CVSS2: 5
7%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1791

Microsoft Internet Explorer 6 SP2 (6.0.2900.2180) crashes when the user attempts to add a URI to the restricted zone, in which the full domain name of the URI begins with numeric sequences similar to an IP address. NOTE: if there is not an exploit scenario in which an attacker can trigger this behavior, then perhaps this issue should not be included in CVE.

CVSS2: 2.6
4%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1790

Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."

CVSS2: 2.6
83%
Высокий
около 21 года назад
nvd логотип
CVE-2005-1789

SQL injection vulnerability in SignIn.asp in India Software Solution shopping cart allows remote attackers to execute arbitrary SQL commands via the password.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1788

SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1787

setup.php in phpStat 1.5 allows remote attackers to bypass authentication and gain administrator privileges by setting the $check variable.

CVSS2: 7.5
12%
Средний
около 21 года назад
nvd логотип
CVE-2005-1786

SQL injection vulnerability in admin.asp in FunkyASP AD System 1.1 allows remote attackers to execute arbitrary SQL commands and gain privileges via the password parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1785

SQL injection vulnerability in ad/login.asp in ZonGG 1.2 allows remote attackers to execute arbitrary SQL commands via the password parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1784

Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.

CVSS2: 7.5
6%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1783

BookReview beta 1.0 allows remote attackers to obtain the path of the web server via certain parameters to search.htm, possibly due to a search[string] parameter with a missing value or an incorrect submit[type] value, which reveals the path in the resulting error message. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1782

Multiple cross-site scripting (XSS) vulnerabilities in BookReview beta 1.0 allow remote attackers to inject arbitrary web script or HTML via the node parameter to (1) add_review.htm, (2) suggest_review.htm, (3) suggest_category.htm, (4) add_booklist.htm, or (5) add_url.htm, the isbn parameter to (6) add_review.htm, (7) add_contents.htm, (8) add_classification.htm, the (9) chapters parameter to the add_contents page in index.php (aka add_contents.htm), (10) the user parameter to contact.htm, or (11) the submit[string] parameter to search.htm. NOTE: it is not clear whether BookReview is available to the public. If not, then it should not be included in CVE.

CVSS2: 4.3
5%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1781

Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).

CVSS2: 5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1780

SQL injection vulnerability in admin/login.asp in Active News Manager allows remote attackers to execute arbitrary SQL commands via the password.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1779

SQL injection vulnerability in password.asp in MaxWebPortal 1.35, 1.36, 2.0, and 20050418 Next allows remote attackers to execute arbitrary SQL commands via the memKey parameter.

CVSS2: 7.5
2%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1778

Cross-site scripting (XSS) vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to inject arbitrary web script or HTML via the start parameter.

CVSS2: 2.6
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1777

SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands via the start parameter.

CVSS2: 7.5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1776

Buffer overflow in the READ_TCP_STRING function in game_message_functions.cpp in the network plugin for C'Nedra 0.4.0 and earlier allows remote attackers to execute arbitrary code via a long text string.

CVSS2: 7.5
4%
Низкий
около 21 года назад

Уязвимостей на страницу