Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 372 504

Количество 372 504

nvd логотип

CVE-2005-0436

больше 21 года назад

Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0435

больше 21 года назад

awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0434

больше 21 года назад

Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2005-0433

больше 21 года назад

Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0432

больше 21 года назад

BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0431

больше 21 года назад

Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0430

больше 21 года назад

The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0429

больше 21 года назад

Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0428

больше 21 года назад

The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0427

больше 21 года назад

The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0426

больше 21 года назад

Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0425

больше 21 года назад

Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0424

больше 21 года назад

Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0423

больше 21 года назад

SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-0422

больше 21 года назад

DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-0421

больше 21 года назад

DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2005-0420

больше 21 года назад

Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.

CVSS2: 5.8
EPSS: Средний
nvd логотип

CVE-2005-0419

больше 21 года назад

Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0418

больше 21 года назад

Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0417

больше 21 года назад

Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a duplicate of other issues as reported by the vendor.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2005-0436

Direct code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the PluginMode parameter.

CVSS2: 7.5
7%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0435

awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to rawlog.

CVSS2: 5
7%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0434

Multiple cross-site scripting (XSS) vulnerabilities in Php-Nuke 7.5 allow remote attackers to inject arbitrary HTML or web script via (1) the newdownloadshowdays parameter in a NewDownloads operation or (2) the newlinkshowdays parameter in a NewLinks operation.

CVSS2: 4.3
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0433

Php-Nuke 7.5 allows remote attackers to determine the full path of the web server via invalid or missing arguments to (1) db.php, (2) mainfile.php, (3) Downloads/index.php, or (4) Web_Links/index.php, which lists the path in a PHP error message.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0432

BEA WebLogic Server 7.0 Service Pack 5 and earlier, and 8.1 Service Pack 3 and earlier, generates different login exceptions that suggest why an authentication attempt fails, which makes it easier for remote attackers to guess passwords via brute force attacks.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0431

Barracuda Spam Firewall 3.1.10 and earlier does not restrict the domains that white-listed domains can send mail to, which allows members of white-listed domains to use Barracuda as an open mail relay for spam.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0430

The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.

CVSS2: 5
8%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0429

Direct code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote attackers to execute inject arbitrary PHP commands via the comma parameter.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0428

The DNSPacket::expand method in dnspacket.cc in PowerDNS before 2.9.17 allows remote attackers to cause a denial of service by sending a random stream of bytes.

CVSS2: 5
3%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0427

The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0426

Unknown vulnerability in Solaris 8 and 9 allows remote attackers to cause a denial of service (panic) via "Heavy UDP Usage" that triggers a NULL dereference.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0425

Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.

CVSS2: 5
2%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0424

Unknown vulnerability in the delete.asp program in certain versions of ASPjar Guestbook allows remote attackers to delete messages. NOTE: there is insufficient information to know if this is the same issue as CVE-2002-1730.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0423

SQL injection vulnerability in login.asp in ASPjar Guestbook allows remote attackers to execute arbitrary SQL commands via the password field.

CVSS2: 5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0422

DelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to gain privileges.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0421

DelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.

CVSS2: 2.1
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0420

Microsoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a link to the owalogon.asp application.

CVSS2: 5.8
26%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0419

Multiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as demonstrated using the STAT command.

CVSS2: 7.5
4%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0418

Argument injection vulnerability in Java Web Start for J2SE 1.4.2 up to 1.4.2_06, on Mac OS X, allows untrusted applications to gain privileges via the value parameter of a property tag in a JNLP file. NOTE: it is highly likely that this item will be MERGED with CVE-2005-0836.

CVSS2: 7.5
1%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0417

Unknown "high risk" vulnerability in DB2 Universal Database 8.1 and earlier has unknown impact and attack vectors. NOTE: due to the delayed disclosure of details for this issue, this candidate may be SPLIT in the future. In addition, this may be a duplicate of other issues as reported by the vendor.

CVSS2: 10
2%
Низкий
больше 21 года назад

Уязвимостей на страницу