CSV
184,074 results for "vulnerability" Page 159
CVE-2005-2715

Format string vulnerability in the Java user interface service (bpjava-msvc) daemon for VERITAS NetBackup Data and Business Center 4.5FP and 4.5MP, and NetBackup Enterprise/Server/Client 5.0, 5.1, and 6.0, allows remote attackers to execute arbitrary code via the COMMAND_LOGON_TO_MSERVER command.

Oct 12, 2005 5 affected product(s) NVD
10.0
CVSS
60.4%
EPSS
⚡ 58.1
CVE-2005-2661

Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows remote IMAP servers to execute arbitrary code via format string specifiers in a banner or capability line.

Oct 14, 2005 2 affected product(s) NVD
7.5
CVSS
12.1%
EPSS
⚡ 33.6
CVE-2005-2967

Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allows remote servers to execute arbitrary code via format string specifiers in metadata in CDDB server responses when the victim plays a CD.

Oct 14, 2005 5 affected product(s) NVD
7.5
CVSS
9.7%
EPSS
⚡ 32.9
CVE-2005-3154

Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.

Oct 5, 2005 3 affected product(s) NVD
7.5
CVSS
3.5%
EPSS
⚡ 31.1
CVE-2005-3157

SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL commands via the msg_send parameter, a different vulnerability than CVE-2005-3158 and CVE-2005-3159.

Oct 6, 2005 1 affected product(s) NVD
7.5
CVSS
3.6%
EPSS
⚡ 31.1
CVE-2005-3150

Format string vulnerability in the Log_Flush function in Weex 2.6.1.5, 2.6.1, and possibly other versions allows remote FTP servers to execute arbitrary code via format strings in filenames.

Oct 5, 2005 2 affected product(s) NVD
7.5
CVSS
2.6%
EPSS
⚡ 30.8
CVE-2005-3158

SQL injection vulnerability in messages.php in PHP-Fusion 6.00.106 and 6.00.107 allows remote attackers to execute arbitrary SQL commands via the (1) pm_email_notify and (2) pm_save_sent parameters, a different vulnerability than CVE-2005-3157 and CVE-2005-3159.

Oct 6, 2005 2 affected product(s) NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.6
CVE-2005-3153

login.php in myBloggie 2.1.3 beta and earlier allows remote attackers to bypass a whitelist regular expression and conduct SQL injection attacks via a username parameter with SQL after a null character, which causes the whitelist check to succeed but injects the SQL into a query string, a different vulnerability than CVE-2005-2838. NOTE: it is possible that this is actually a bug in PHP code, in which case this should not be treated as a myBloggie vulnerability.

Oct 5, 2005 1 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.5
CVE-2005-3201

SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary SQL via the newsid parameter.

Oct 14, 2005 NVD
7.5
CVSS
1.8%
EPSS
⚡ 30.5
CVE-2005-3082

SQL injection vulnerability in admin.php in SEO-Board 1.0.2 allows remote attackers to execute arbitrary SQL commands via the user_pass_sha1 value in a cookie.

Sep 27, 2005 NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2005-3075

SQL injection vulnerability in Zengaia before 0.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Sep 27, 2005 8 affected product(s) NVD
7.5
CVSS
1.1%
EPSS
⚡ 30.3
CVE-2005-3130

SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.

Oct 4, 2005 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.3
CVE-2005-3159

SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.

Oct 6, 2005 NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.3
CVE-2005-1980

Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."

Oct 12, 2005 9 affected product(s) NVD
5.0
CVSS
33.3%
EPSS
⚡ 30
CVE-2005-3086

Directory traversal vulnerability in admin/about.php in contentServ 3.1 allows remote attackers to read or include arbitrary files via ".." sequences in the ctsWebsite parameter.

Sep 27, 2005 1 affected product(s) NVD
6.4
CVSS
1.9%
EPSS
⚡ 26.2
CVE-2005-2710

Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via the (1) image handle or (2) timeformat attribute in a RealPix (.rp) or RealText (.rt) file.

Sep 27, 2005 2 affected product(s) NVD
5.1
CVSS
13.2%
EPSS
⚡ 24.4
CVE-2005-3204

Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.

Oct 14, 2005 53 affected product(s) NVD
4.3
CVSS
20.7%
EPSS
⚡ 23.4
CVE-2005-3129

Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.

Oct 4, 2005 1 affected product(s) NVD
5.1
CVSS
5.5%
EPSS
⚡ 22
CVE-2005-3100

Unspecified "PPTP Remote DoS Vulnerability" in Astaro Security Linux 4.027 allows attackers to cause a denial of service.

Sep 28, 2005 1 affected product(s) NVD
5.0
CVSS
1.8%
EPSS
⚡ 20.6
CVE-2005-3136

Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename.

Oct 4, 2005 1 affected product(s) NVD
5.0
CVSS
2.1%
EPSS
⚡ 20.6
← Previous Page 159 of 9204 Next →