Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 596

Количество 372 596

nvd логотип

CVE-2005-1152

около 21 года назад

popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-1151

около 21 года назад

qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2005-1150

больше 21 года назад

Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1149

больше 21 года назад

SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1148

больше 21 года назад

calendar.pl in CalendarScript 3.21 allows remote attackers to obtain sensitive information via invalid (1) year or (2) month parameters, which leaks the full pathname and debug information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1147

больше 21 года назад

calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1146

больше 21 года назад

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1145

больше 21 года назад

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1144

больше 21 года назад

popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1143

больше 21 года назад

Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1142

больше 21 года назад

Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1141

больше 21 года назад

Integer overflow in the readpgm function in pnm.c for GOCR 0.40, when using the netpbm library, allows remote attackers to execute arbitrary code via a PNM file with large width and height values, which leads to a heap-based buffer overflow.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2005-1140

больше 21 года назад

Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1139

больше 21 года назад

Opera 8 Beta 3, when using first-generation vetted digital certificates, displays the Organizational information of an SSL certificate, which is easily spoofed and can facilitate phishing attacks.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1138

больше 21 года назад

Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain e-mail messages.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1137

больше 21 года назад

Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1136

больше 21 года назад

Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and crack passwords via a direct request to these files.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1135

больше 21 года назад

Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-1134

больше 21 года назад

SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1133

больше 21 года назад

The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-1152

popauth.c in qpopper 4.0.5 and earlier does not properly set the umask, which may cause qpopper to create files with group or world-writable permissions.

CVSS2: 2.1
0%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1151

qpopper 4.0.5 and earlier does not properly drop privileges before processing certain user-supplied files, which allows local users to overwrite or create arbitrary files as root.

CVSS2: 7.2
0%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1150

Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier, when running on Windows systems, allows attackers to cause a denial of service (hang).

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1149

SQL injection vulnerability in admin/login.asp in aspclick.it ACNews 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1148

calendar.pl in CalendarScript 3.21 allows remote attackers to obtain sensitive information via invalid (1) year or (2) month parameters, which leaks the full pathname and debug information.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1147

calendar.pl in CalendarScript 3.20 allows remote attackers to obtain sensitive information via invalid (1) calendar or (2) template parameters, which leaks the full pathname and debug information.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1146

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in the login command in calendar.pl in CalendarScript 3.21 allows remote attackers to inject arbitrary web script or HTML via the username parameter, a different vulnerability than CVE-2005-1145

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1145

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in calendar.pl in CalendarScript 3.20 allows remote attackers to inject arbitrary web script or HTML via the template parameter, a different vulnerability than CVE-2005-1146

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1144

popup.php in EasyPHPCalendar before 6.2.8 allows remote attackers to obtain sensitive information via an invalid ev parameter, which reveals the full pathname of the web server in a PHP error message.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1143

Cross-site scripting (XSS) vulnerability in index.php in EasyPHPCalendar before 6.2.8 allows remote attackers to inject arbitrary web script or HTML via the yr parameter.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1142

Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values.

CVSS2: 7.5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1141

Integer overflow in the readpgm function in pnm.c for GOCR 0.40, when using the netpbm library, allows remote attackers to execute arbitrary code via a PNM file with large width and height values, which leads to a heap-based buffer overflow.

CVSS3: 9.8
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1140

Cross-site scripting (XSS) vulnerability in myBloggie 2.1.1 allows remote attackers to inject arbitrary web script or HTML via the comments.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1139

Opera 8 Beta 3, when using first-generation vetted digital certificates, displays the Organizational information of an SSL certificate, which is easily spoofed and can facilitate phishing attacks.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1138

Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain e-mail messages.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1137

Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to obtain sensitive information via a direct request to sb_functions.php, which leaks the full pathname in a PHP error message.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1136

Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and crack passwords via a direct request to these files.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1135

Cross-site scripting (XSS) vulnerability in search.php for Simple PHP Blog (sphpBlog) 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1134

SQL injection vulnerability in exit.php for Serendipity 0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) url_id or (2) entry_id parameters.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-1133

The POP3 server in IBM iSeries AS/400 returns different error messages when the user exists or not, which allows remote attackers to determine valid user IDs on the server.

CVSS2: 5
2%
Низкий
больше 21 года назад

Уязвимостей на страницу