Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 504

Количество 372 504

nvd логотип

CVE-2005-0456

больше 21 года назад

Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0455

больше 21 года назад

Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value.

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2005-0454

больше 21 года назад

Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.php, or (2) the mid or bid parameters to forums.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0453

больше 21 года назад

The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0452

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2005-0451

больше 21 года назад

Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0450

больше 21 года назад

Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0449

больше 21 года назад

The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.

CVSS2: 7.1
EPSS: Низкий
nvd логотип

CVE-2005-0448

больше 21 года назад

Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.

CVSS2: 1.2
EPSS: Низкий
nvd логотип

CVE-2005-0447

больше 21 года назад

Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0446

больше 21 года назад

Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2005-0445

больше 21 года назад

Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0444

больше 21 года назад

VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2005-0443

больше 21 года назад

index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0442

больше 21 года назад

Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0441

больше 21 года назад

Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2005-0440

больше 21 года назад

ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0439

больше 21 года назад

Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-0438

больше 21 года назад

awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0437

больше 21 года назад

Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-0456

Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0455

Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1 allows remote attackers to execute arbitrary code via a .SMIL file with a large system-screen-size value.

CVSS2: 5.1
54%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0454

Multiple SQL injection vulnerabilities in DCP-Portal 6.1.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the lcat, doc, or uid parameters to index.php, or (2) the mid or bid parameters to forums.php.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0453

The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0452

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII characters, including ">" and "<".

CVSS2: 4.3
23%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0451

Sami HTTP Server 1.0.5 allows remote attackers to cause a denial of service via an HTTP request containing two CRLF sequences, which triggers a NULL dereference.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0450

Directory traversal vulnerability in Sami HTTP Server 1.0.5 allows remote attackers to read arbitrary files via an HTTP request containing (1) .. (dot dot) or (2) "%2e%2e" (encoded dot dot) sequences.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0449

The netfilter/iptables module in Linux before 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) or bypass firewall rules via crafted packets, which are not properly handled by the skb_checksum_help function.

CVSS2: 7.1
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0448

Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.

CVSS2: 1.2
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0447

Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0446

Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.

CVSS2: 5
41%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0445

Cross-site scripting (XSS) vulnerability in Open WebMail 2.x allows remote attackers to inject arbitrary HTML or web script via the domain name parameter (logindomain) in the login page.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0444

VMware before 4.5.2.8848-r5 searches for gdk-pixbuf shared libraries using a path that includes the rrdharan world-writable temporary directory, which allows local users to execute arbitrary code.

CVSS2: 4.6
0%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0443

index.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting (XSS) attacks via an invalid language parameter, which echoes the parameter in a PHP error message.

CVSS2: 4.3
5%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0442

Directory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language parameter.

CVSS2: 5
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0441

Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a crafted query plan, or remote authenticated users with database owner or "sa" role privileges to execute arbitrary code via (5) a crafted install java statement.

CVSS2: 10
9%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0440

ELOG before 2.5.7 allows remote attackers to bypass authentication and download a configuration file that contains a sensitive write password via a modified URL.

CVSS2: 7.5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0439

Buffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with long file names.

CVSS2: 7.5
10%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0438

awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.

CVSS2: 5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0437

Directory traversal vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to include arbitrary Perl modules via .. (dot dot) sequences in the loadplugin parameter.

CVSS2: 7.5
2%
Низкий
больше 21 года назад

Уязвимостей на страницу