CVE-2005-0 to CVE-2005-999
261 CVEs with public proof-of-concept exploits.
- CVE-2005-00212 PoCsMultiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8…
- CVE-2005-00221 PoCBuffer overflow in the spa_base64_to_bits function in Exim before 4.43, as originally obtained from Samba code, and as called by the…
- CVE-2005-00231 PoCgnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable.…
- CVE-2005-00433 PoCsBuffer overflow in Apple iTunes 4.7 allows remote attackers to execute arbitrary code via a long URL in (1) .m3u or (2) .pls playlist files.
- CVE-2005-00451 PoCThe Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB…
- CVE-2005-00472 PoCsWindows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows…
- CVE-2005-00483 PoCsMicrosoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial…
- CVE-2005-00531 PoCInternet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop…
- CVE-2005-00581 PoCBuffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows…
- CVE-2005-00593 PoCsBuffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary…
- CVE-2005-00631 PoCThe document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote…
- CVE-2005-01013 PoCsBuffer overflow in the socket_getline function in Newspost 2.1.1 and earlier allows remote malicious NNTP servers to execute arbitrary…
- CVE-2005-01051 PoCUnknown vulnerability in typespeed 0.4.1 and earlier allows local users to gain privileges.
- CVE-2005-01165 PoCsAWStats 6.1, and other versions before 6.3, allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2005-01291 PoCThe Quick Buttons feature in Konversation 0.15 allows remote attackers to execute certain IRC commands via a channel name containing "%"…
- CVE-2005-01551 PoCThe PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to create arbitrary files via the…
- CVE-2005-01561 PoCBuffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute…
- CVE-2005-01611 PoCMultiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archive containing (1)…
- CVE-2005-01831 PoCftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters…
- CVE-2005-01841 PoCDirectory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary…
- CVE-2005-01851 PoCStack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap…
- CVE-2005-01931 PoCBuffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute…
- CVE-2005-01991 PoCInteger underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service…
- CVE-2005-02261 PoCFormat string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to…
- CVE-2005-02292 PoCsCitrusDB 0.3.5 and earlier stores the newfile.txt temporary data file under the web root, which allows remote attackers to steal credit…
- CVE-2005-02451 PoCBuffer overflow in gram.y for PostgreSQL 8.0.0 and earlier may allow attackers to execute arbitrary code via a large number of arguments…
- CVE-2005-02514 PoCsCross-site scripting (XSS) vulnerability in bibindex.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to…
- CVE-2005-02523 PoCsSQL injection vulnerability in BibORB 1.3.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via…
- CVE-2005-02533 PoCsDirectory traversal vulnerability in index.php for BibORB 1.3.2, and possibly earlier versions, allows remote attackers to delete…
- CVE-2005-02542 PoCsBibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows…
- CVE-2005-02561 PoCThe wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by…
- CVE-2005-02602 PoCsStack-based buffer overflow in the Discovery Service for BrightStor ARCserve Backup 11.1 and earlier allows remote attackers to execute…
- CVE-2005-02621 PoCBuffer overflow in ipl_varyon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -d argument.
- CVE-2005-02631 PoCBuffer overflow in netpmon on AIX 5.1, 5.2, and 5.3 allows local users to execute arbitrary code via a long -O argument.
- CVE-2005-02701 PoCMultiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitrary web…
- CVE-2005-02711 PoCMultiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the…
- CVE-2005-02721 PoCReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple…
- CVE-2005-02731 PoCMultiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL…
- CVE-2005-02741 PoCMultiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inject arbitrary…
- CVE-2005-02774 PoCsBuffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application…
- CVE-2005-02801 PoCFormat string vulnerability in Soldner Secret Wars 30830 and earlier allows remote attackers to cause a denial of service (server crash)…
- CVE-2005-02831 PoCDirectory traversal vulnerability in index.php in QwikiWiki allows remote attackers to read arbitrary files via a .. (dot dot) and a %00…
- CVE-2005-03052 PoCsCRLF injection vulnerability in users.php in Siteman 1.1.10 and earlier allows remote attackers to add arbitrary users and gain privileges…
- CVE-2005-03071 PoCMultiple cross-site scripting (XSS) vulnerabilities in index.php in MercuryBoard 1.1.1 allow remote attackers to inject arbitrary web…
- CVE-2005-03082 PoCsBuffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code via a large import…
- CVE-2005-03121 PoCWarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a…
- CVE-2005-03132 PoCsMultiple directory traversal vulnerabilities in Magic Winmail Server 4.0 Build 1112 allow remote attackers to (1) upload arbitrary files…
- CVE-2005-03162 PoCsWebWasher Classic 2.2.1 and 3.3, when running in server mode, does not properly drop CONNECT requests to the localhost from external…
- CVE-2005-03202 PoCsMultiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject…
- CVE-2005-03252 PoCsXpand Rally 1.0.0.0 allows remote attackers or remote malicious game servers to cause a denial of service (application crash) via a packet…
- CVE-2005-03301 PoCBuffer overflow in Painkiller 1.35 and earlier, and possibly other versions before 1.61, allows remote authenticated users to cause a…
- CVE-2005-03384 PoCsBuffer overflow in Savant Web Server 3.1 allows remote attackers to execute arbitrary code via a long HTTP request.
- CVE-2005-03391 PoCBuffer overflow in Foxmail 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long MAIL…
- CVE-2005-03401 PoCInteger signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a…
- CVE-2005-03421 PoCThe Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the…
- CVE-2005-03431 PoCSQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter.
- CVE-2005-03441 PoCDirectory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files…
- CVE-2005-03451 PoCviewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view…
- CVE-2005-03534 PoCsBuffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary…
- CVE-2005-03561 PoCMultiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote…
- CVE-2005-03681 PoCMultiple SQL injection vulnerabilities in CMScore allow remote attackers to execute arbitrary SQL commands via the (1) EntryID or (2)…
- CVE-2005-03691 PoCArmagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application…
- CVE-2005-03701 PoCArmagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network…
- CVE-2005-03751 PoCimageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2)…
- CVE-2005-03761 PoCPHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by…
- CVE-2005-03821 PoCBreed patch 1 and earlier allows remote attackers to cause a denial of service (application crash) via an empty UDP packet, which triggers…
- CVE-2005-03851 PoCBuffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a…
- CVE-2005-04042 PoCsKMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or…
- CVE-2005-04061 PoCA design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an…
- CVE-2005-04071 PoCCross-site scripting (XSS) vulnerability in Openconf 1.04, and possibly other versions before 1.10, allows remote attackers to inject…
- CVE-2005-04082 PoCsCitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers…
- CVE-2005-04093 PoCsCitrusDB 0.3.6 and earlier does not verify authorization for the (1) importcc.php and (2) uploadcc.php, which allows remote attackers to…
- CVE-2005-04102 PoCsSQL injection vulnerability in importcc.php for CitrusDB 0.3.6 and earlier allows remote attackers to inject data via the fields of a CSV…
- CVE-2005-04112 PoCsDirectory traversal vulnerability in index.php for CitrusDB 0.3.6 and earlier allows remote attackers and local users to include arbitrary…
- CVE-2005-04132 PoCsMultiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in…
- CVE-2005-04141 PoCSQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post…
- CVE-2005-04163 PoCsThe Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allows…
- CVE-2005-04191 PoCMultiple heap-based buffer overflows in 3Com 3CServer allow remote authenticated users to execute arbitrary code via long FTP commands, as…
- CVE-2005-04201 PoCMicrosoft Outlook Web Access (OWA), when used with Exchange, allows remote attackers to redirect users to arbitrary URLs for login via a…
- CVE-2005-04211 PoCDelphiTurk FTP 1.0 stores usernames and passwords in the profile.dat file, which allows local users to gain privileges.
- CVE-2005-04221 PoCDelphiTurk CodeBank (aka KodBank) 3.1 and earlier stores usernames and passwords in the Codebank registry key, which allows local users to…
- CVE-2005-04292 PoCsDirect code injection vulnerability in forumdisplay.php in vBulletin 3.0 through 3.0.4, when showforumusers is enabled, allows remote…
- CVE-2005-04301 PoCThe Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and…
- CVE-2005-04351 PoCawstats.pl in AWStats 6.3 and 6.4 allows remote attackers to read server web logs by setting the loadplugin and pluginmode parameters to…
- CVE-2005-04361 PoCDirect code injection vulnerability in awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to execute portions of Perl code via the…
- CVE-2005-04381 PoCawstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter.
- CVE-2005-04391 PoCBuffer overflow in the decode_post function in ELOG before 2.5.7 allows remote attackers to execute arbitrary code via attachments with…
- CVE-2005-04421 PoCDirectory traversal vulnerability in index.php for CubeCart 2.0.4 allows remote attackers to read arbitrary files via the language…
- CVE-2005-04431 PoCindex.php in CubeCart 2.0.4 allows remote attackers to (1) obtain the full path for the web server or (2) conduct cross-site scripting…
- CVE-2005-04521 PoCMultiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject…
- CVE-2005-04553 PoCsStack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlayer 10.5…
- CVE-2005-04641 PoCgr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug…
- CVE-2005-04651 PoCgr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s…
- CVE-2005-04681 PoCHeap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute…
- CVE-2005-04754 PoCsSQL injection vulnerability in paFAQ Beta4, and possibly other versions, allows remote attackers to execute arbitrary SQL code via the (1)…
- CVE-2005-04772 PoCsCross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to inject arbitrary…
- CVE-2005-04782 PoCsMultiple buffer overflows in TrackerCam 5.12 and earlier allow remote attackers to cause a denial of service and possibly execute…
- CVE-2005-04791 PoCDirectory traversal vulnerability in ComGetLogFile.php3 for TrackerCam 5.12 and earlier allows remote attackers to read arbitrary files…
- CVE-2005-04917 PoCsStack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.
- CVE-2005-04931 PoCCRLF injection vulnerability in bizmail.cgi in Biz Mail Form before 2.2 allows remote attackers to bypass the email check and send spam…
- CVE-2005-04941 PoCThe RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly…
- CVE-2005-05011 PoCBuffer overflow in Bontago 1.1 and earlier allows remote attackers to execute arbitrary code via a long nickname.
- CVE-2005-05061 PoCThe Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a registry key,…
- CVE-2005-05113 PoCsmisc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute…
- CVE-2005-05131 PoCPHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and possibly other…
- CVE-2005-05171 PoCPeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users to gain privileges.
- CVE-2005-05182 PoCseXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local users to gain…
- CVE-2005-05211 PoCSendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to…
- CVE-2005-05221 PoCChat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users…
- CVE-2005-05231 PoCFormat string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers…
- CVE-2005-05434 PoCsCross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the…
- CVE-2005-05481 PoCCross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject…
- CVE-2005-05491 PoCCross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject…
- CVE-2005-05511 PoCStack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1…
- CVE-2005-05531 PoCRace condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows…
- CVE-2005-05541 PoCBuffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service…
- CVE-2005-05551 PoCBuffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code…
- CVE-2005-05602 PoCsHeap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003…
- CVE-2005-05661 PoCBuffer overflow in Golden FTP Server Pro (goldenftpd) 2.x allows remote attackers to execute arbitrary code via a long RNTO command.
- CVE-2005-05682 PoCsSoldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_guid value, which…
- CVE-2005-05691 PoCMultiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) language…
- CVE-2005-05731 PoCGaim 1.1.3 on Windows systems allows remote attackers to cause a denial of service (client crash) via a file transfer in which the…
- CVE-2005-05758 PoCsBuffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possibly execute…
- CVE-2005-05815 PoCsMultiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execute arbitrary code…
- CVE-2005-05821 PoCBuffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename…
- CVE-2005-05953 PoCsBuffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand parameter.
- CVE-2005-06021 PoCUnzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain…
- CVE-2005-06031 PoCviewtopic.php in phpBB 2.0.12 and earlier allows remote attackers to obtain sensitive information via a highlight parameter containing…
- CVE-2005-06061 PoCCross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows…
- CVE-2005-06132 PoCsUnknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
- CVE-2005-06144 PoCssessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.
- CVE-2005-06192 PoCsEinstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows local users to gain…
- CVE-2005-06211 PoCScrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is…
- CVE-2005-06291 PoCMultiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitrary web script or…
- CVE-2005-06322 PoCsPHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP…
- CVE-2005-06331 PoCBuffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image file.
- CVE-2005-06343 PoCsBuffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.
- CVE-2005-06351 PoCBuffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.
- CVE-2005-06361 PoCFormat string vulnerability in Foxmail Server 2.0 allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2005-06431 PoCBuffer overflow in McAfee Scan Engine 4320 with DAT version before 4357 allows remote attackers to execute arbitrary code via crafted LHA…
- CVE-2005-06471 PoCadmin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2)…
- CVE-2005-06501 PoCMultiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2005-06661 PoCUnknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC and VMA mirroring,…
- CVE-2005-06702 PoCsCross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web script or HTML…
- CVE-2005-06711 PoCFormat string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to execute arbitrary…
- CVE-2005-06781 PoCPHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers to execute…
- CVE-2005-06801 PoCPHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute…
- CVE-2005-06811 PoCNokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.
- CVE-2005-06842 PoCsMultiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an…
- CVE-2005-06882 PoCsWindows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption)…
- CVE-2005-06893 PoCsincluder.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the URL or (2) the…
- CVE-2005-06911 PoCPHP remote file inclusion vulnerability in article mode for modules.php in SocialMPN allows remote attackers to execute arbitrary PHP code…
- CVE-2005-06931 PoCBuffer overflow in JoWood Chaser 1.50 and earlier allows remote attackers to cause a denial of service (client or server crash) and…
- CVE-2005-06981 PoCPHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying…
- CVE-2005-06991 PoCMultiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and…
- CVE-2005-07001 PoCThe export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by setting the…
- CVE-2005-07011 PoCDirectory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrary files via…
- CVE-2005-07091 PoCMySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to execute arbitrary…
- CVE-2005-07101 PoCMySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library…
- CVE-2005-07111 PoCMySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, uses predictable file names when creating temporary tables, which allows local users…
- CVE-2005-07131 PoCThe Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users…
- CVE-2005-07162 PoCsStack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local…
- CVE-2005-07201 PoCPHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitrary PHP code by…
- CVE-2005-07253 PoCsSQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows remote attackers to…
- CVE-2005-07311 PoCPY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumption) via a direct…
- CVE-2005-07351 PoCnewsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.
- CVE-2005-07363 PoCsInteger overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large…
- CVE-2005-07371 PoCBuffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.
- CVE-2005-07391 PoCThe IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could…
- CVE-2005-07411 PoCCross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2005-07504 PoCsThe bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local…
- CVE-2005-07683 PoCsBuffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows…
- CVE-2005-07711 PoCVERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by…
- CVE-2005-07732 PoCsStack-based buffer overflow in VERITAS Backup Exec Remote Agent 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for Netware…
- CVE-2005-07761 PoCadm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which could allow…
- CVE-2005-07791 PoCPlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple…
- CVE-2005-07801 PoCpaFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) auth.php, (2) login.php, (3)…
- CVE-2005-07812 PoCsSQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute…
- CVE-2005-07822 PoCsCross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows remote attackers to…
- CVE-2005-07831 PoCCross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2005-07861 PoCSQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the quote parameter to…
- CVE-2005-07881 PoCLimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.
- CVE-2005-07911 PoCCross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows remote attackers…
- CVE-2005-07921 PoCSQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter to…
- CVE-2005-07951 PoCHolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite arbitrary files via…
- CVE-2005-07961 PoCDirectory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/votes" followed by…
- CVE-2005-08001 PoCPHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbitrary PHP code by…
- CVE-2005-08021 PoCCross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute arbitrary web…
- CVE-2005-08032 PoCsThe GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash)…
- CVE-2005-08041 PoCFormat string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) via format string…
- CVE-2005-08051 PoCSQL injection vulnerability in index.php in Subdreamer Light, when magic_quotes_gpc is enabled, allows remote attackers to execute…
- CVE-2005-08151 PoCMultiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cause a denial of…
- CVE-2005-08181 PoCCross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email…
- CVE-2005-08232 PoCsThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which…
- CVE-2005-08281 PoChighlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xoops (exoops),…
- CVE-2005-08291 PoCCross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject…
- CVE-2005-08311 PoCPHP-Post allows remote attackers to spoof the names of other users by registering with a username containing hex-encoded characters.
- CVE-2005-08381 PoCMultiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute…
- CVE-2005-08411 PoCSQL injection vulnerability in (1) people.php, (2) track.php, (3) edit.php, (4) document.php, (5) census.php, (6) passthru.php and…
- CVE-2005-08421 PoCCross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.3 allows remote attackers to inject arbitrary web script or…
- CVE-2005-08431 PoCCRLF injection vulnerability in search.php in Phorum 5.0.14a allows remote attackers to perform HTTP Response Splitting attacks via the…
- CVE-2005-08471 PoCCode Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.
- CVE-2005-08482 PoCsMultiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution,…
- CVE-2005-08491 PoCMultiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution,…
- CVE-2005-08501 PoCFileZilla FTP server before 0.9.6 allows remote attackers to cause a denial of service via a request for a filename containing an MS-DOS…
- CVE-2005-08511 PoCFileZilla FTP server before 0.9.6, when using MODE Z (zlib compression), allows remote attackers to cause a denial of service (infinite…
- CVE-2005-08521 PoCMicrosoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket…
- CVE-2005-08532 PoCsbetaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive information via a…
- CVE-2005-08542 PoCsbetaparticle blog (bp blog), posisbly before version 4, allows remote attackers to bypass authentication and (1) upload files via a direct…
- CVE-2005-08571 PoCCross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web…
- CVE-2005-08581 PoCMultiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the…
- CVE-2005-08592 PoCsPHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the tpath parameter to…
- CVE-2005-08601 PoCPHP remote file inclusion vulnerability in TRG News Script 3.0 allows remote attackers to execute arbitrary PHP code via the dir parameter…
- CVE-2005-08624 PoCsMultiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code…
- CVE-2005-08631 PoCCross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the…
- CVE-2005-08702 PoCsMultiple cross-site scripting (XSS) vulnerabilities in phpSysInfo 2.3, when register_globals is enabled, allow remote attackers to inject…
- CVE-2005-08721 PoCCross-site scripting (XSS) vulnerability in calendar_scheduler.php in the Topic Calendar 1.0.1 module for phpBB allows remote attackers to…
- CVE-2005-08731 PoCMultiple cross-site scripting (XSS) vulnerabilities in test.jsp in Oracle Reports Server 10g (9.0.4.3.3) allow remote attackers to inject…
- CVE-2005-08792 PoCsPHP remote file include vulnerability in (1) content.php and (2) index.php for Vortex Portal allows remote attackers to execute arbitrary…
- CVE-2005-08811 PoCCross-site scripting (XSS) vulnerability in articles.newcomment for Interspire ArticleLive 2005 allows remote attackers to inject…
- CVE-2005-08832 PoCsMultiple cross-site scripting (XSS) vulnerabilities in base.php for DigitalHive 2.0 allow remote attackers to inject arbitrary web script…
- CVE-2005-08861 PoCCross-site scripting (XSS) vulnerability in Invision Power Board 2.0.2 and earlier allows remote attackers to inject arbitrary web script…
- CVE-2005-08871 PoCEval injection vulnerability in Double Choco Latte before 0.9.4.3 allows remote attackers to execute arbitrary PHP code via the menuAction…
- CVE-2005-08891 PoCCross-site scripting (XSS) vulnerability in index.php for Dream4 Koobi CMS 4.2.3 allows remote attackers to inject arbitrary web script or…
- CVE-2005-08903 PoCsSQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the area parameter.
- CVE-2005-08922 PoCsBuffer overflow in smail 3.2.0.120 allows remote attackers or local users to execute arbitrary code via a long string in the MAIL FROM…
- CVE-2005-08941 PoCOpenmosixCollector and OpenMosixView in OpenMosixView 1.5 allow local users to overwrite or delete arbitrary files via a symlink attack on…
- CVE-2005-08951 PoCNetcomm 1300NB DSL Modem allows remote attackers to cause a denial of service (device hang) via a large number of ping packets.
- CVE-2005-08961 PoCMultiple cross-site scripting (XSS) vulnerabilities in review.php in phpMyDirectory 10.1.3-rel allow remote attackers to inject arbitrary…
- CVE-2005-09031 PoCBuffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file…
- CVE-2005-09041 PoCRemote Desktop in Windows XP SP1 does not verify the "Force shutdown from a remote system" setting, which allows remote attackers to shut…
- CVE-2005-09051 PoCMaxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.
- CVE-2005-09061 PoCBuffer overflow in a player logging function in the Tincat network library 2.x before 2.0.28, as used in games such as Sacred and The…
- CVE-2005-09161 PoCAIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of…
- CVE-2005-09251 PoCCross-site scripting (XSS) vulnerability in login.asp for Ublog Reload 1.0 through 1.0.4 allows remote attackers to inject arbitrary web…
- CVE-2005-09283 PoCsMultiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web script or HTML…
- CVE-2005-09293 PoCsSQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter…
- CVE-2005-09311 PoCPHP remote file inclusion vulnerability in The Includer 1.0 and 1.1 allows remote attackers to execute arbitrary PHP code.
- CVE-2005-09352 PoCsMultiple SQL injection vulnerabilities in ESMI PayPal Storefront allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2005-09361 PoCCross-site scripting vulnerability in products1h.php in ESMI PayPal Storefront allows remote attackers to inject arbitrary web script or…
- CVE-2005-09443 PoCsUnknown vulnerability in Microsoft Jet DB engine (msjet40.dll) 4.00.8618.0, related to insufficient data validation, allows remote…
- CVE-2005-09451 PoCCross-site scripting (XSS) vulnerability in ACS Blog 1.1.1 allows remote attackers to inject arbitrary web script or HTML via onmouseover…
- CVE-2005-09481 PoCSQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id…
- CVE-2005-09501 PoCDirectory traversal vulnerability in FastStone 4in1 Browser 1.2 allows remote attackers to read arbitrary files via a (1) ... (triple dot)…
- CVE-2005-09521 PoCCross-site scripting vulnerability in pafiledb.php in PaFileDB 3.1 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2005-09551 PoCSQL injection vulnerability in InterAKT MX Shop 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id_ctg parameter.
- CVE-2005-09581 PoCFormat string vulnerability in the log_do function in log.c for YepYep mtftpd 0.0.3, when the statistics option is enabled, allows remote…
- CVE-2005-09591 PoCBuffer overflow in the mt_do_dir function in YepYep mtftpd 0.0.3 may allow attackers to execute arbitrary code via a long path.
- CVE-2005-09621 PoCSQL injection vulnerability in index.php for Lighthouse Squirrelcart allows remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2005-09781 PoCDirectory traversal vulnerability in the Object Push service in IVT BlueSoleil 1.4 allows remote attackers to upload arbitrary files via a…
- CVE-2005-09791 PoCMultiple buffer overflows in RUMBA 7.3 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code…
- CVE-2005-09801 PoCPHP remote file inclusion vulnerability in index.php in AlstraSoft EPay Pro 2.0 allows remote attackers to execute arbitrary PHP code by…
- CVE-2005-09811 PoCMultiple cross-site scripting (XSS) vulnerabilities in AlstraSoft EPay Pro 2.0 allow remote attackers to inject arbitrary web script or…
- CVE-2005-09842 PoCsBuffer overflow in the G_Printf function in Star Wars Jedi Knight: Jedi Academy 1.011 and earlier allows remote attackers to execute…
- CVE-2005-09861 PoCNLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a…
- CVE-2005-09891 PoCThe find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows…
- CVE-2005-09921 PoCCross-site scripting (XSS) vulnerability in index.php in phpMyAdmin before 2.6.2-rc1 allows remote attackers to inject arbitrary web…
- CVE-2005-09931 PoCBuffer overflow in nwprint in SCO OpenServer 5.0.7 allows local users to execute arbitrary code via a long command line argument.
- CVE-2005-09942 PoCsMultiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (1) the Category or…
- CVE-2005-09971 PoCMultiple SQL injection vulnerabilities in the Web_Links module for PHP-Nuke 7.6 allow remote attackers to execute arbitrary SQL commands…
- CVE-2005-09991 PoCSQL injection vulnerability in the Top module for PHP-Nuke 6.x through 7.6 allows remote attackers to execute arbitrary SQL commands via…