Total
29527 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2005-2505 | 1 Apple | 1 Mac Os X | 2008-09-05 | 7.5 HIGH | N/A |
Buffer overflow in CoreFoundation in Mac OS X 10.3.9 allows attackers to execute arbitrary code via command line arguments to an application that uses CoreFoundation. | |||||
CVE-2005-2509 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2008-09-05 | 2.1 LOW | N/A |
Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts. | |||||
CVE-2005-2501 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2008-09-05 | 7.6 HIGH | N/A |
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file. | |||||
CVE-2005-2516 | 1 Apple | 2 Mac Os X, Safari | 2008-09-05 | 7.5 HIGH | N/A |
Safari in Mac OS X 10.3.9 and 10.4.2, when rendering Rich Text Format (RTF) files, can directly access URLs without performing the normal security checks, which allows remote attackers to execute arbitrary commands. | |||||
CVE-2005-2198 | 1 Spid | 1 Spid | 2008-09-05 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in lang.php in SPiD before 1.3.1 allows remote attackers to execute arbitrary code via the lang_path parameter. | |||||
CVE-2005-2200 | 1 Xerox | 3 Workcentre 2128, Workcentre 2636, Workcentre 3545 | 2008-09-05 | 7.5 HIGH | N/A |
Multiple unknown vulnerabilities in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to bypass authentication. | |||||
CVE-2005-2252 | 1 Gianluca Baldo | 1 Phpauction | 2008-09-05 | 7.5 HIGH | N/A |
PhpAuction 2.5 allows remote attackers to bypass authentication and gain privileges as another user by setting the PHPAUCTION_RM_ID cookie to the user ID. | |||||
CVE-2005-2207 | 1 Elemental Software | 1 Cartwiz | 2008-09-05 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in store/login.asp in CartWIZ allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |||||
CVE-2005-2199 | 1 Skrypty | 1 Ppa Gallery | 2008-09-05 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable. | |||||
CVE-2005-2283 | 1 Esi Products | 1 Webeoc | 2008-09-05 | 2.1 LOW | N/A |
WebEOC before 6.0.2 does not properly restrict the size of an uploaded file, which allows remote authenticated users to cause a denial of service (system and database resource consumption) via a large file. | |||||
CVE-2005-2154 | 1 Osticket | 1 Osticket Sts | 2008-09-05 | 7.5 HIGH | N/A |
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to include and possibly execute arbitrary local files via the inc parameter. | |||||
CVE-2005-2217 | 1 Craig Dansie | 1 Dansie Shopping Cart | 2008-09-05 | 5.0 MEDIUM | N/A |
Dansie Shopping Cart stores the vars.dat file under the web root with insufficient access control, which might allow remote attackers to obtain sensitive information such as program variables. | |||||
CVE-2005-2233 | 1 Ibm | 1 Aix | 2008-09-05 | 7.2 HIGH | N/A |
Buffer overflow in multiple "p" commands in IBM AIX 5.1, 5.2 and 5.3 might allow local users to execute arbitrary code via long command line arguments to (1) penable or other hard-linked files including (2) pdisable, (3) pstart, (4) phold, (5) pdelay, or (6) pshare. | |||||
CVE-2005-2523 | 1 Apple | 2 Mac Os X, Weblog Server | 2008-09-05 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Weblog Server in Mac OS X 10.4 to 10.4.2 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. | |||||
CVE-2005-2146 | 1 Ssh | 1 Tectia Server | 2008-09-05 | 4.6 MEDIUM | N/A |
SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server. | |||||
CVE-2005-2512 | 1 Apple | 2 Mac Os X, Mail | 2008-09-05 | 2.1 LOW | N/A |
Mail.app in Mac OS 10.4.2 and earlier, when printing or forwarding an HTML message, loads remote images even when the user's preferences state otherwise, which could result in a privacy leak. | |||||
CVE-2005-2174 | 1 Mozilla | 1 Bugzilla | 2008-09-05 | 2.6 LOW | N/A |
Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete. | |||||
CVE-2005-2226 | 1 Microsoft | 1 Outlook Express | 2008-09-05 | 5.0 MEDIUM | N/A |
Microsoft Outlook Express 6.0 leaks the default news server account when a user responds to a "watched" conversation thread, which could allow remote attackers to obtain sensitive information. | |||||
CVE-2005-2520 | 1 Apple | 1 Mac Os X | 2008-09-05 | 2.1 LOW | N/A |
The password assistant in Mac OS X 10.4 to 10.4.2, when used to create multiple accounts from the same process, does not reset the suggested password list when the assistant is displayed, which allows attackers to view recently used passwords. | |||||
CVE-2005-2328 | 1 Laffer | 1 Laffer | 2008-09-05 | 5.0 MEDIUM | N/A |
PHP remote file inclusion vulnerability in im.php in Laffer 0.3.2.6 and 0.3.2.7 allows remote attackers to execute arbitrary PHP code via the CFG_PATH variable. |