CSV
182,725 results for "vulnerability" Page 132
CVE-2005-1344

Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.

May 2, 2005 1 affected product(s) NVD
7.5
CVSS
29.1%
EPSS
⚡ 38.7
CVE-2005-1370

Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.

May 3, 2005 2 affected product(s) NVD
7.5
CVSS
5.6%
EPSS
⚡ 31.7
CVE-2005-1401

Format string vulnerability in the client for Mtp-Target 1.2.2 and earlier allows remote attackers to execute arbitrary code via game messages or other text.

May 3, 2005 1 affected product(s) NVD
7.5
CVSS
4.1%
EPSS
⚡ 31.2
CVE-2005-1360

PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP code by modifying the path_prefix parameter to reference a URL on a remote web server that contains the code.

May 2, 2005 1 affected product(s) NVD
7.5
CVSS
3.0%
EPSS
⚡ 30.9
CVE-2005-1409

PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."

May 3, 2005 28 affected product(s) NVD
7.5
CVSS
2.0%
EPSS
⚡ 30.6
CVE-2005-1378

SQL injection vulnerability in posting_notes.php in the notes module for phpBB allows remote attackers to execute arbitrary SQL commands via the p parameter, which is used in the $post_id variable, and other attack vectors.

May 3, 2005 1 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2005-1397

SQL injection vulnerability in search.php for PHP-Calendar before 0.10.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

May 3, 2005 11 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2005-1439

Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.

May 3, 2005 1 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2005-1302

SQL injection vulnerability in Confixx 3.08 and earlier allows remote attackers to execute arbitrary SQL commands via the "change user" field.

May 2, 2005 3 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-1419

SQL injection vulnerability in the admin login panel for Ocean12 Mailing List Manager 1.06 allows remote attackers to execute arbitrary SQL commands via the Admin_id parameter.

May 3, 2005 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-1429

SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.

May 3, 2005 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-1438

PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.

May 3, 2005 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2005-1412

SQL injection vulnerability in verify.asp for Ecomm Professional Guestbook 3.x allows remote attackers to execute arbitrary SQL commands via the AdminPWD parameter.

May 3, 2005 1 affected product(s) NVD
7.5
CVSS
1.0%
EPSS
⚡ 30.3
CVE-2005-1394

Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.

May 3, 2005 1 affected product(s) NVD
7.2
CVSS
0.8%
EPSS
⚡ 29
CVE-2005-1380

Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web script or HTML via the server parameter to a JndiFramesetAction action.

May 3, 2005 15 affected product(s) NVD
6.8
CVSS
5.0%
EPSS
⚡ 28.7
CVE-2005-1423

Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary files via .. sequences in the A parameter.

May 3, 2005 1 affected product(s) NVD
6.4
CVSS
2.8%
EPSS
⚡ 26.4
CVE-2005-1243

Directory traversal vulnerability in the third party tool from SafeStone, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.

May 2, 2005 1 affected product(s) NVD
5.0
CVSS
1.8%
EPSS
⚡ 20.5
CVE-2005-1416

Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.

May 3, 2005 1 affected product(s) NVD
5.0
CVSS
1.6%
EPSS
⚡ 20.5
CVE-2005-1421

Directory traversal vulnerability in Raysoft/Raybase Video Cam Server 1.0.0 beta allows remote attackers to read arbitrary files via ".." (dot dot) sequences in an HTTP request.

May 3, 2005 1 affected product(s) NVD
5.0
CVSS
1.5%
EPSS
⚡ 20.5
CVE-2005-1441

Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).

May 3, 2005 9 affected product(s) NVD
5.0
CVSS
1.8%
EPSS
⚡ 20.5
← Previous Page 132 of 9137 Next →