CSV
184,048 results for "vulnerability" Page 146
CVE-2005-1689 CRITICAL

Double free vulnerability in the krb5_recvauth function in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to execute arbitrary code via certain error conditions.

Jul 18, 2005 5 affected product(s) NVD
9.8
CVSS
11.0%
EPSS
⚡ 42.5
CVE-2005-1850

Certain contributed scripts for ekg Gadu Gadu client 1.5 and earlier create temporary files insecurely, with unknown impact and attack vectors, a different vulnerability than CVE-2005-1916.

Jul 19, 2005 11 affected product(s) NVD
10.0
CVSS
1.5%
EPSS
⚡ 40.5
CVE-2005-2222

Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.

Jul 12, 2005 10 affected product(s) NVD
10.0
CVSS
1.4%
EPSS
⚡ 40.4
CVE-2005-2249

Multiple unknown vulnerabilities in Jinzora 2.0.1 have unknown impact and attack vectors, possibly involving a PHP file inclusion vulnerability.

Jul 13, 2005 1 affected product(s) NVD
10.0
CVSS
1.3%
EPSS
⚡ 40.4
CVE-2005-2223

Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.

Jul 12, 2005 17 affected product(s) NVD
5.0
CVSS
50.8%
EPSS
⚡ 35.2
CVE-2005-2251

PHP remote file inclusion vulnerability in secure.php in PHPSecurePages (phpSP) 0.28beta and earlier allows remote attackers to execute arbitrary code via the cfgProgDir parameter, a variant of CVE-2001-1468.

Jul 13, 2005 18 affected product(s) NVD
7.5
CVSS
4.9%
EPSS
⚡ 31.5
CVE-2005-2258

PHP remote file inclusion vulnerability in photolist.inc.php in Squito Gallery 1.33 allows remote attackers to execute arbitrary code via the photoroot parameter.

Jul 13, 2005 1 affected product(s) NVD
7.5
CVSS
3.2%
EPSS
⚡ 31
CVE-2005-2216

PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.

Jul 12, 2005 1 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2005-2321

PHP remote file inclusion vulnerability in CaLogic 1.2.2 allows remote attackers to execute arbitrary code via the CLPATH parameter to (1) cl_minical.php, (2) clmcpreload.php, (3) mcconfig.php, or (4) mcpi-demo.php.

Jul 19, 2005 1 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2005-2245

Unknown vulnerability in F5 BIG-IP 9.0.2 through 9.1 allows attackers to "subvert the authentication of SSL transactions," via unknown attack vectors, possibly involving NATIVE ciphers.

Jul 12, 2005 5 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2005-2253

SQL injection vulnerability in PhpAuction 2.5 allow remote attackers to modify SQL queries via the category parameter to adsearch.php. NOTE: there is evidence that viewnews.php may not be part of the PhpAuction product, so it is not included in this description.

Jul 13, 2005 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-2236

Format string vulnerability in the paginit command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via format strings in command line arguments.

Jul 12, 2005 1 affected product(s) NVD
7.2
CVSS
1.1%
EPSS
⚡ 29.1
CVE-2005-2237

Format string vulnerability in the swcons command in IBM AIX 5.3, and possibly other versions, might allow local users to execute arbitrary code via long command line arguments.

Jul 12, 2005 NVD
7.2
CVSS
0.4%
EPSS
⚡ 28.9
CVE-2005-2307

netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."

Jul 19, 2005 13 affected product(s) NVD
5.0
CVSS
25.6%
EPSS
⚡ 27.7
CVE-2005-2371

Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.

Jul 26, 2005 4 affected product(s) NVD
5.0
CVSS
22.3%
EPSS
⚡ 26.7
CVE-2005-2255

Directory traversal vulnerability in PhpAuction 2.5 allows remote attackers to read arbitrary files, include local PHP files, or obtain sensitive path information via ".." sequences in the lan parameter to (1) index.php or (2) admin/index.php.

Jul 13, 2005 1 affected product(s) NVD
6.4
CVSS
1.5%
EPSS
⚡ 26.1
CVE-2005-2330

Directory traversal vulnerability in extras/update.php in osCommerce 2.2 allows remote attackers to read arbitrary files via (1) .. sequences or (2) a full pathname in the readme_file parameter.

Jul 20, 2005 1 affected product(s) NVD
5.0
CVSS
9.6%
EPSS
⚡ 22.9
CVE-2005-2378

Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.

Jul 26, 2005 1 affected product(s) NVD
5.0
CVSS
9.1%
EPSS
⚡ 22.7
CVE-2005-2256

Encoded directory traversal vulnerability in phpPgAdmin 3.1 to 3.5.3 allows remote attackers to access arbitrary files via "%2e%2e%2f" (encoded dot dot) sequences in the formLanguage parameter.

Jul 13, 2005 6 affected product(s) NVD
5.0
CVSS
4.6%
EPSS
⚡ 21.4
CVE-2005-2195

Apple Darwin Streaming Server 5.5 and earlier allows remote attackers to cause a denial of service (application crash) via a URL with a filename containing a .cgi extension and an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1, a different vulnerability than CVE-2003-0421 and CVE-2003-0502.

Jul 18, 2005 1 affected product(s) NVD
5.0
CVSS
1.6%
EPSS
⚡ 20.5
← Previous Page 146 of 9203 Next →