CSV
184,269 results for "vulnerability" Page 190
CVE-2005-4560 Exploit

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.

Dec 28, 2005 16 affected product(s) NVD
7.5
CVSS
86.1%
EPSS
⚡ 65.8
CVE-2005-4565

Format string vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation in ADTRAN NetVanta before 10.03.03.E might allow remote attackers to have an unknown impact via format string specifiers in crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.

Dec 29, 2005 3 affected product(s) NVD
10.0
CVSS
2.5%
EPSS
⚡ 40.7
CVE-2005-4573

PHP remote file include vulnerability in plog-admin-functions.php in Plogger Beta 2 allows remote attackers to execute arbitrary code via a URL in the config[basedir] parameter.

Dec 29, 2005 1 affected product(s) NVD
7.5
CVSS
11.7%
EPSS
⚡ 33.5
CVE-2005-4556

PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enabled, allows remote attackers to include arbitrary local and remote PHP files via a URL in the (1) lang_settings and (2) language parameters in (a) accounts/inc/include.php and (b) admin/inc/include.php.

Dec 28, 2005 3 affected product(s) NVD
7.5
CVSS
10.4%
EPSS
⚡ 33.1
CVE-2005-4585

Unspecified vulnerability in the GTP dissector for Ethereal 0.9.1 to 0.10.13 allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.

Dec 29, 2005 30 affected product(s) NVD
7.8
CVSS
4.5%
EPSS
⚡ 32.5
CVE-2005-4546

search.php in eggblog 2.0 allows remote attackers to obtain the full path via an invalid q parameter, as used by the Keyword and Search fields, possibly due to an SQL injection vulnerability.

Dec 28, 2005 1 affected product(s) NVD
7.8
CVSS
1.6%
EPSS
⚡ 31.7
CVE-2005-4582

Electric Sheep 2.6.3 does not require authentication or integrity checks from the server to the client, which allows remote attackers to download and display arbitrary MPEG movie files via (1) DNS spoofing, (2) a URL on the command line, or (3) a URL in the configuration file. NOTE: the same attack vectors apply to common web browsers that are able to communicate with untrusted web servers, and other problems related to DNS design issues. Therefore this may not be a specific vulnerability. However, a client would reasonably expect to receive content only from the server.

Dec 29, 2005 1 affected product(s) NVD
7.5
CVSS
1.7%
EPSS
⚡ 30.5
CVE-2005-4500

SQL injection vulnerability in MusicBox 2.3 allows remote attackers to execute arbitrary SQL commands via the (1) show and (2) type parameter. NOTE: the provenance of this information is unknown, although it was later rediscovered.

Dec 22, 2005 1 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-3536

SQL injection vulnerability in phpBB 2 before 2.0.18 allows remote attackers to execute arbitrary SQL commands via the topic type.

Dec 22, 2005 27 affected product(s) NVD
7.5
CVSS
1.3%
EPSS
⚡ 30.4
CVE-2005-4509

SQL injection vulnerability in index.asp in pTools allows remote attackers to execute arbitrary SQL commands via the docID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Dec 23, 2005 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-4515

SQL injection vulnerability in WebDB 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search parameters, possibly Search0. NOTE: the vendor has disputed this issue, saying that "WebDB is a generic online database system used by many of the clients of Lois Software. The flaw that was identified was some code that was added for a client to do some testing of his system and only certain safe commands were allowed. This code has now been removed and it is not now possible to use SQL queries as part of the query string. No installation or patch is required All clients use a common code library and have their own front end and databases and connections. So as soon as a change / upgrade / enhancement is made to the code, all users of the software begin to use the latest changes immediately." Since the issue appeared in a custom web site and no action is required on the part of customers, this issue should not be included in CVE

Dec 23, 2005 2 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2005-4528

SQL injection vulnerability in the Chatspot 2.0.0a7 module for phpBB allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Dec 28, 2005 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-4533

Argument injection vulnerability in scponlyc in scponly 4.1 and earlier, when both scp and rsync compatibility are enabled, allows local users to execute arbitrary applications via "getopt" style argument specifications, which are not filtered.

Dec 28, 2005 8 affected product(s) NVD
7.5
CVSS
1.5%
EPSS
⚡ 30.4
CVE-2005-4548

SQL injection vulnerability in the "user area" in RWS Statistics Counter before 2.4.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

Dec 28, 2005 1 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.4
CVE-2005-4563

SQL injection vulnerability in main.php in Enterprise Heart Enterprise Connector 1.0.2 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the loginid parameter, a different vulnerability than CVE-2005-3875.

Dec 29, 2005 1 affected product(s) NVD
7.5
CVSS
1.4%
EPSS
⚡ 30.4
CVE-2005-4517

SQL injection vulnerability in PHP-Fusion 6.00.200 through 6.00.300 allows remote attackers to execute arbitrary SQL commands via the ratings parameter in multiple scripts, such as ratings_include.php.

Dec 28, 2005 4 affected product(s) NVD
7.5
CVSS
1.2%
EPSS
⚡ 30.3
CVE-2005-4505

Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.

Dec 23, 2005 2 affected product(s) NVD
7.2
CVSS
1.0%
EPSS
⚡ 29.1
CVE-2005-1528

Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.

Dec 31, 2005 1 affected product(s) NVD
7.2
CVSS
0.8%
EPSS
⚡ 29.1
CVE-2005-1755

PHP remote file inclusion vulnerability in poll_vote.php in PHP Poll Creator 1.01 allows remote attackers to execute arbitrary PHP code via the relativer_pfad parameter.

Dec 31, 2005 1 affected product(s) NVD
6.4
CVSS
2.5%
EPSS
⚡ 26.3
CVE-2005-4557

dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local files via a null byte (%00) in the lang parameter, possibly due to a directory traversal vulnerability.

Dec 28, 2005 3 affected product(s) NVD
5.0
CVSS
9.5%
EPSS
⚡ 22.8
← Previous Page 190 of 9214 Next →