Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-4730 Remote Security vulnerability in Pear Text Password 1.0
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds.
network
low complexity
pear
critical
10.0
2005-12-31 CVE-2005-4729 SQL Injection vulnerability in Vbzoom 1.11
SQL injection vulnerability in show.php in VBZooM Forum allows remote attackers to execute arbitrary SQL commands via the SubjectID parameter.
network
low complexity
vbzoom
7.5
2005-12-31 CVE-2005-4728 Local Code Execution vulnerability in Debian Amaya 9.2.1.6
Untrusted search path vulnerability (RPATH) in amaya 9.2.1 on Debian GNU/Linux allows local users to gain privileges via a malicious Mesa library in the /home/anand directory.
local
low complexity
debian
4.6
2005-12-31 CVE-2005-4727 Cross-Site Scripting vulnerability in Gbook 1.0/1.0.1
Cross-site scripting (XSS) vulnerability in gbook.cgi in gBook before 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header field.
network
high complexity
martin-bauer
5.1
2005-12-31 CVE-2005-4726 Information Disclosure vulnerability in Mute 0.4
MUTE 0.4 uses improper flood protection algorithms, which allows remote attackers to obtain sensitive information (privacy leak and search result data) by controlling a drop chain neighbor that is near the end of a message chain.
network
low complexity
mute
5.0
2005-12-31 CVE-2005-4725 Security Bypass vulnerability in Geeklog (Extended Japanese Package)
Geeklog before 1.3.11sr3 allows remote attackers to bypass intended access restrictions and comment on an arbitrary story or topic by guessing the story ID.
network
low complexity
geeklog
7.5
2005-12-31 CVE-2005-4724 SQL injection vulnerability in post.php in PhpTagCool 1.0.3 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field in an HTTP header.
network
low complexity
phptagcool
7.5
2005-12-31 CVE-2005-4722 Information Disclosure vulnerability in Tmspublisher 3.0/3.3
_Request_Message.cfm in tmsPUBLISHER 3.3 allows remote attackers to obtain sensitive information via an invalid id argument to pagename.cfm, which reveals the installation path in an error message.
network
low complexity
the-media-shoppe-berhad
5.0
2005-12-31 CVE-2005-4721 Cross-Site Scripting vulnerability in the Media Shoppe Berhad Tmspublisher 3.3
Cross-site scripting (XSS) vulnerability in search.cfm in tmsPUBLISHER 3.3 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
4.3
2005-12-31 CVE-2005-4720 Denial Of Service vulnerability in Mozilla Firefox IFRAME Handling
Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large value of the WIDTH attribute, which triggers a problem related to representation of floating-point numbers, leading to an infinite loop of widget resizes and a corresponding large number of function calls on the stack.
network
low complexity
mozilla
5.0