CSV
184,066 results for "vulnerability" Page 156
CVE-2005-2878

Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.

Sep 13, 2005 1 affected product(s) NVD
7.5
CVSS
14.6%
EPSS
⚡ 34.4
CVE-2005-3010

Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code via the HTTP_CLIENT_IP header (Client-Ip), which is injected into data/flood.db.php.

Sep 21, 2005 1 affected product(s) NVD
7.5
CVSS
6.3%
EPSS
⚡ 31.9
CVE-2005-2951

Directory traversal vulnerability in security.inc.php in AzDGDatingLite 2.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary PHP commands via ".." sequences and "%00" (trailing null byte) characters in the l parameter, which is used in an include_once statement.

Sep 16, 2005 1 affected product(s) NVD
7.5
CVSS
3.1%
EPSS
⚡ 30.9
CVE-2005-2870

Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.

Sep 8, 2005 1 affected product(s) NVD
7.5
CVSS
2.8%
EPSS
⚡ 30.8
CVE-2005-2893

Direct static code injection vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code via the username (u parameter), which is directly injected into a file that is later executed upon login.

Sep 14, 2005 1 affected product(s) NVD
7.5
CVSS
2.7%
EPSS
⚡ 30.8
CVE-2005-2983

SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL commands via the values in the parameter form that appears when the paramform parameter is set to yes.

Sep 20, 2005 1 affected product(s) NVD
7.5
CVSS
2.2%
EPSS
⚡ 30.7
CVE-2005-2987

SQL injection vulnerability in login.php in Digital Scribe 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.

Sep 20, 2005 1 affected product(s) NVD
7.5
CVSS
1.9%
EPSS
⚡ 30.6
CVE-2005-2954

SQL injection vulnerability in password_reminder.php in ATutor before 1.5.1 pl1 allows remote attackers to execute arbitrary SQL commands via the email field.

Sep 16, 2005 1 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2005-2896

SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.

Sep 14, 2005 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-2902

SQL injection vulnerability in class-1 Forum Software 0.24.4 allows remote attackers to execute arbitrary SQL commands and bypass the file extension check via SQL code in the file extension of an uploaded file.

Sep 14, 2005 NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-0138

rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not correctly allow access to anonymous clients that connect from a system whose hostname can not be determined. NOTE: while this issue occurs in a security mechanism, there is no apparent attacker role and probably does not satisfy the CVE definition of a vulnerability.

Sep 21, 2005 3 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-0139

Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, which allows attackers to conduct unauthorized activities.

Sep 21, 2005 3 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-3003

SQL injection vulnerability in index.php in NooTopList 1.0.0 release 17 allows remote attackers to execute arbitrary SQL commands via the (1) o or (2) sort parameters.

Sep 21, 2005 NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-2979

SQL injection vulnerability in index.php in phpoutsourcing Noah's classifieds allows remote attackers to execute arbitrary SQL commands via the rollid parameter.

Sep 20, 2005 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.3
CVE-2005-2985

SQL injection vulnerability in search_result.php in AEwebworks aeDating Script 4.0 and earlier allows remote attackers to execute arbitrary SQL statements via the Country parameter.

Sep 20, 2005 2 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.3
CVE-2005-3004

SQL injection vulnerability in Interakt MX Shop 3.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) idp, (2) id_ctg, or (3) id_prd parameters to the pages module in index.php.

Sep 21, 2005 1 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2005-2994

Unspecified vulnerability in the web client for IBM Rational ClearQuest 2002.05.00 and 2002.05.20, and 2003.06.00 through 2003.06.15 before SR5, allows remote attackers to execute XML Style Sheets (XSS).

Sep 20, 2005 8 affected product(s) NVD
6.8
CVSS
1.1%
EPSS
⚡ 27.5
CVE-2005-2872

The ipt_recent kernel module (ipt_recent.c) in Linux kernel before 2.6.12, when running on 64-bit processors such as AMD64, allows remote attackers to cause a denial of service (kernel panic) via certain attacks such as SSH brute force, which leads to memset calls using a length based on the u_int32_t type, acting on an array of unsigned long elements, a different vulnerability than CVE-2005-2873.

Sep 9, 2005 61 affected product(s) NVD
5.0
CVSS
3.9%
EPSS
⚡ 21.2
CVE-2005-2952

Directory traversal vulnerability in s.pl in Subscribe Me Pro 2.044.09P and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.

Sep 16, 2005 1 affected product(s) NVD
5.0
CVSS
3.6%
EPSS
⚡ 21.1
CVE-2005-3026

Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the read parameter.

Sep 21, 2005 1 affected product(s) NVD
5.0
CVSS
3.6%
EPSS
⚡ 21.1
← Previous Page 156 of 9204 Next →