Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-4740 Multiple vulnerability in IBM DB2 Universal Database
IBM DB2 Universal Database (UDB) 810 before version 8 FixPak 10 allows remote authenticated users to cause a denial of service (db2jd service crash) by "connecting from a downlevel client."
network
low complexity
ibm
4.0
2005-12-31 CVE-2005-4739 Multiple vulnerability in IBM DB2 Universal Database
IBM DB2 Universal Database (UDB) 820 before version 8 FixPak 10 (s050811) allows remote authenticated users to cause a denial of service (application crash) by using a table function for an instance of snapshot_tbreorg, which triggers a trap in sqlnr_EStoE_action.
network
low complexity
ibm
6.8
2005-12-31 CVE-2005-4738 Multiple vulnerability in IBM DB2 Universal Database
IBM DB2 Universal Database (UDB) 810 before ESE AIX 5765F4100 does not ensure that a user has execute privileges before permitting object creation based on routines, which allows remote authenticated users to gain privileges.
network
low complexity
ibm
6.5
2005-12-31 CVE-2005-4737 Multiple vulnerability in IBM DB2 Universal Database
IBM DB2 Universal Database (UDB) 820 before ESE AIX 5765F4100 allows remote authenticated users to cause a denial of service (CPU consumption) by "abnormally" terminating a connection, which prevents db2agents from being properly cleared.
network
low complexity
ibm
7.5
2005-12-31 CVE-2005-4736 Multiple vulnerability in IBM DB2 Universal Database
IBM DB2 Universal Database (UDB) 820 before 8.2 FP10 allows remote authenticated users to cause a denial of service (disk consumption) via a hash join (hsjn) that triggers an infinite loop in sqlri_hsjnFlushBlocks.
network
low complexity
ibm
6.8
2005-12-31 CVE-2005-4735 Multiple vulnerability in IBM DB2 Universal Database
IBM DB2 Universal Database (UDB) 810 before 8.1 FP10 allows remote authenticated users to cause a denial of service (application crash) via (1) certain equality predicates that trigger self-removal, aka IY70808; and (2) a query with more than 32000 elements in the IN-list, aka LI70817.
network
low complexity
ibm
6.8
2005-12-31 CVE-2005-4734 Remote Stack Based Buffer Overflow vulnerability in RSA Authentication Agent IISWebAgentIF.DLL
Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3 for IIS allows remote attackers to execute arbitrary code via a long url parameter in the Redirect method.
network
low complexity
rsa
6.4
2005-12-31 CVE-2005-4733 Denial-Of-Service vulnerability in Netbsd 2.0
NetBSD 2.0 before 20050316 and NetBSD-current before 20050112 allow local users to cause a denial of service (infinite loop and system hang) by calling the F_CLOSEM fcntl with a parameter value of 0.
local
low complexity
netbsd
4.9
2005-12-31 CVE-2005-4732 Cross-Site Scripting vulnerability in Tuxbank
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Tux Racer TuxBank 0.7x and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) description parameters.
network
tux-racer
4.3
2005-12-31 CVE-2005-4731 Remote Security vulnerability in the PHP Group Pear Html Quickform Controller 1.0.4
The Next action in PEAR HTML_QuickForm_Controller 1.0.4 includes the SID in the URL even when session.use_only_cookies is configured, which allows remote attackers to obtain the SID via an HTTP Referer field and possibly other vectors.
network
low complexity
the-php-group
5.0