Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 504

Количество 372 504

nvd логотип

CVE-2005-0477

больше 21 года назад

Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0476

больше 21 года назад

Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0475

больше 21 года назад

SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-0474

больше 21 года назад

SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2005-0473

больше 21 года назад

The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0472

больше 21 года назад

Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0471

больше 21 года назад

Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0470

больше 21 года назад

Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0469

больше 21 года назад

Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0468

больше 21 года назад

Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-0467

больше 21 года назад

Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0465

больше 21 года назад

gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-0464

больше 21 года назад

gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-0463

больше 21 года назад

Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port.php, and (3) index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0462

больше 21 года назад

Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0461

больше 21 года назад

Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0460

больше 21 года назад

index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0459

больше 21 года назад

phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0458

больше 21 года назад

Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0457

больше 21 года назад

Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory.

CVSS2: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-0477

Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary web script via (1) a signature file or (2) a message post containing an IMG tag within a COLOR tag whose style is set to background:url.

CVSS2: 4.3
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0476

Cross-site scripting (XSS) vulnerability in hpm_guestbook.cgi allows remote attackers to inject arbitrary web script or HTML by posting a message.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0475

SQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1) offset, (2) limit, (3) order, or (4) orderby parameter to question.php, (5) offset parameter to answer.php, (6) search_item parameter to search.php, (7) cat_id, (8) cid, or (9) id parameter to comment.php.

CVSS2: 6.4
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0474

SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.

CVSS2: 6.4
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0473

The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0472

Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.

CVSS2: 5
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0471

Sun Java JRE 1.1.x through 1.4.x writes temporary files with long filenames that become predictable on a file system that uses 8.3 style short names, which allows remote attackers to write arbitrary files to known locations and facilitates the exploitation of vulnerabilities in applications that rely on unpredictable file names.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0470

Buffer overflow in wpa_supplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0469

Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.

CVSS2: 7.5
9%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0468

Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.

CVSS2: 7.5
27%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0467

Multiple integer overflows in the (1) sftp_pkt_getstring and (2) fxp_readdir_recv functions in the PSFTP and PSCP clients for PuTTY 0.56, and possibly earlier versions, allow remote malicious web sites to execute arbitrary code via SFTP responses that corrupt the heap after insufficient memory has been allocated.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0465

gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0464

gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0463

Unknown "major security flaws" in Ulog-php before 1.0, related to input validation, have unknown impact and attack vectors, probably related to SQL injection vulnerabilities in (1) host.php, (2) port.php, and (3) index.php.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0462

Cross-site scripting (XSS) vulnerability in MercuryBoard 1.0.x and 1.1.x allows remote attackers to inject arbitrary HTML and web script via the f parameter.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0461

Unknown vulnerability in NewsBruiser 2.x before 2.6.1 allows remote attackers to "take actions on comments."

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0460

index.php in MercuryBoard 1.0.x and 1.1.x allows remote attackers to obtain sensitive information by setting the debug parameter.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0459

phpMyAdmin 2.6.2-dev, and possibly earlier versions, allows remote attackers to determine the full path of the web root via a direct request to select_lang.lib.php, which reveals the path in a PHP error message.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0458

Cross-site scripting (XSS) vulnerability in contact_us.php in osCommerce 2.2-MS2 allows remote attackers to inject arbitrary web script or HTML via the enquiry parameter.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0457

Opera 7.54 and earlier on Gentoo Linux uses an insecure path for plugins, which could allow local users to gain privileges by inserting malicious libraries into the PORTAGE_TMPDIR (portage) temporary directory.

CVSS2: 7.2
0%
Низкий
больше 21 года назад

Уязвимостей на страницу