Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-4816 Buffer Overflow vulnerability in ProFTPD Mod_Radius
Buffer overflow in mod_radius in ProFTPD before 1.3.0rc2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.
network
low complexity
proftpd-project
7.5
2005-12-31 CVE-2005-4815 Remote Security vulnerability in Sap R 3
SAP 6.4 before 6.40 patch 4, 6.2 before 6.20 patch 1364, 4.6 before 4.6D patch 1767, 45 before 45B patch 913, 40 before 40B patch 1008, and 31 before 31I patch 735 do not properly restrict process execution by lnaxdm/sapsys, which allows remote attackers to execute arbitrary code via a certain UDP packet that ends with the name of a local executable file, aka the "FX SAP R/3 gwrd vuln."
network
low complexity
sap
7.5
2005-12-31 CVE-2005-4814 File-Upload vulnerability in Segue Cms
Unrestricted file upload vulnerability in Segue CMS before 1.3.6, when the Apache HTTP Server handles .phtml files with the PHP interpreter, allows remote attackers to upload and execute arbitrary PHP code by placing .phtml files in the userfiles/ directory.
network
low complexity
middlebury-college
7.5
2005-12-31 CVE-2005-4813 Denial Of Service vulnerability in Business Objects Enterprise/Crystal Reports Server
Unspecified vulnerability in Report Application Server (Crystalras.exe) before 11.0.0.1370, as used in Business Objects Crystal Reports XI, Crystal Reports Server XI, and BusinessObjects Enterprise XI, allows remote attackers to cause a denial of service (application hang) via certain network traffic, possibly involving multiple simultaneous TCP connections.
network
low complexity
businessobjects
5.0
2005-12-31 CVE-2005-4812 Remote Denial of Service vulnerability in SISCO OSI Stack
The SISCO OSI stack for Windows, as used by MMS-EASE 7.10 and earlier, AX-S4 MMS 5.01 and earlier, AX-S4 ICCP 3.0103 and earlier, and the ICCP Toolkit for MMS-EASE 4.10 and earlier, allows remote attackers to cause a denial of service (process crash) via certain network traffic, as demonstrated using a Nessus scan.
network
low complexity
sisco
7.8
2005-12-31 CVE-2005-4811 Local Denial of Service vulnerability in Linux Kernel UnMap_HugePage_Area
The hugepage code (hugetlb.c) in Linux kernel 2.6, possibly 2.6.12 and 2.6.13, in certain configurations, allows local users to cause a denial of service (crash) by triggering an mmap error before a prefault, which causes an error in the unmap_hugepage_area function.
local
low complexity
linux
4.9
2005-12-31 CVE-2005-4810 Unspecified vulnerability in Microsoft Internet Explorer 7.0
Microsoft Internet Explorer 7.0 Beta3 and earlier allows remote attackers to cause a denial of service (crash) via a "text/html" HTML Content-type header sent in response to an XMLHttpRequest (AJAX).
network
low complexity
microsoft
5.0
2005-12-31 CVE-2005-4809 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.
network
low complexity
mozilla
5.0
2005-12-31 CVE-2005-4808 Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file.
network
high complexity
gnu canonical
7.6
2005-12-31 CVE-2005-4807 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
network
low complexity
gnu canonical CWE-119
7.5