Vulnerabilities (CVE)

Filtered by NVD-CWE-Other
Total 29527 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-3150 1 Weex 1 Weex 2008-09-05 7.5 HIGH N/A
Format string vulnerability in the Log_Flush function in Weex 2.6.1.5, 2.6.1, and possibly other versions allows remote FTP servers to execute arbitrary code via format strings in filenames.
CVE-2005-3115 1 Mpeg-tools 1 Mpeg-tools 2008-09-05 2.1 LOW N/A
mpeg-tools before 1.5b-r2 creates multiple temporary files insecurely, which allows local users to overwrite arbitrary files via (1) ts.stat, (2) ts.mpg, (3) foobar, (4) blockbar, or (5) foobar[NNN].
CVE-2005-3148 2 Storebackup, Suse 2 Storebackup, Suse Linux 2008-09-05 4.6 MEDIUM N/A
StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect ownership.
CVE-2005-3175 1 Microsoft 1 Windows 2000 2008-09-05 7.2 HIGH N/A
Microsoft Windows 2000 before Update Rollup 1 for SP4 allows a local administrator to unlock a computer even if it has been locked by a domain administrator, which allows the local administrator to access the session as the domain administrator.
CVE-2005-3034 1 Compuware 1 Driverstudio 2008-09-05 7.5 HIGH N/A
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session.
CVE-2005-3076 1 Simplog 1 Simplog 2008-09-05 7.5 HIGH N/A
Simplog 0.9.1 might allow remote attackers to execute arbitrary SQL commands or trigger SQL error messages via invalid (1) pid, (2) blogid, (3) cid, or (4) m parameters to archive.php, or the (5) blogid parameter to blogadmin.php.
CVE-2005-3254 1 Nathan Neulinger 1 Cgiwrap 2008-09-05 10.0 HIGH N/A
The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attackers to execute code as other system UIDs that are greater than the minimum value, which should be 1000 on Debian systems.
CVE-2005-3292 1 Xeobook 1 Xeobook 2008-09-05 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Xeobook 0.93 allow remote attackers to inject arbitrary web script or HTML via Javascript events in tages such as <b>.
CVE-2005-2962 1 Ntlmaps 1 Ntlmaps 2008-09-05 2.1 LOW N/A
The post-installation script for ntlmaps before 0.9.9 sets world-readable permissions for the configuration file, which allows local users to obtain the username and password.
CVE-2005-3079 1 Punbb 1 Punbb 2008-09-05 4.6 MEDIUM N/A
PunBB before 1.2.8 allows remote attackers to perform "code inclusion" via the user language selection.
CVE-2005-3086 1 Contentserv 1 Contentserv 2008-09-05 6.4 MEDIUM N/A
Directory traversal vulnerability in admin/about.php in contentServ 3.1 allows remote attackers to read or include arbitrary files via ".." sequences in the ctsWebsite parameter.
CVE-2005-3038 1 Hosting Controller 1 Hosting Controller 2008-09-05 5.0 MEDIUM N/A
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."
CVE-2005-3085 1 Riverdark Studios 1 Rss Syndicator Module 2008-09-05 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in rss.php in Riverdark Studios RSS Syndicator module 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) forum or (2) topic parameters.
CVE-2005-3282 1 Splatt 1 Splatt Forum 2008-09-05 7.5 HIGH N/A
Splatt Forum 3.0 to 3.2 allows remote attackers to bypass authentication via unknown vectors.
CVE-2005-3081 1 Wzdftpd 1 Wzdftpd 2008-09-05 4.6 MEDIUM N/A
wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE command.
CVE-2005-3035 1 Compuware 1 Driverstudio 2008-09-05 5.0 MEDIUM N/A
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110.
CVE-2005-3146 2 Storebackup, Suse 2 Storebackup, Suse Linux 2008-09-05 2.1 LOW N/A
StoreBackup before 1.19 allows local users to perform unauthorized operations on arbitrary files via a symlink attack on temporary files.
CVE-2005-2997 1 Bugada Andrea 1 Php Advanced Transfer Manager 2008-09-05 5.0 MEDIUM N/A
Multiple directory traversal vulnerabilities in PHP Advanced Transfer Manager 1.30 allow remote attackers to read arbitrary files via ".." sequences in (1) the currentdir parameter to txt.php, or the current_dir parameter to (2) htm.php or (3) html.php.
CVE-2005-3102 1 Six Apart 1 Movable Type 2008-09-05 5.0 MEDIUM N/A
The administrative interface in Movable Type allows attackers to upload files with arbitrary extensions under the web root.
CVE-2005-3101 1 Six Apart 1 Movable Type 2008-09-05 5.0 MEDIUM N/A
The password reset feature in Movable Type before 3.2 generates different error messages depending on whether a user exists or not, which allows remote attackers to determine valid usernames.