Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-3711 Numeric Errors vulnerability in Apple Quicktime
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified (1) "strips" (StripByteCounts) or (2) "bands" (StripOffsets) values.
network
low complexity
apple CWE-189
7.5
2005-12-31 CVE-2005-3710 Numeric Errors vulnerability in Apple Quicktime
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via a TIFF image file with modified image height and width (ImageWidth) tags.
network
low complexity
apple CWE-189
7.5
2005-12-31 CVE-2005-3709 Numeric Errors vulnerability in Apple Quicktime
Integer underflow in Apple Quicktime before 7.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Color Map Entry Size in a TGA image file.
network
low complexity
apple CWE-189
7.5
2005-12-31 CVE-2005-3708 Code Execution vulnerability in RETIRED: Apple QuickTime
Integer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.
network
low complexity
apple
7.5
2005-12-31 CVE-2005-3707 Code Execution vulnerability in RETIRED: Apple QuickTime
Buffer overflow in Apple Quicktime before 7.0.4 allows remote attackers to execute arbitrary code via crafted TGA image files.
network
low complexity
apple
7.5
2005-12-31 CVE-2005-3706 Multiple vulnerability in Apple Mac OS X Security Update 2006-001
Heap-based buffer overflow in LibSystem in Mac OS X 10.4 through 10.4.5 allows context-dependent attackers to execute arbitrary code by causing an application that uses LibSystem to request a large amount of memory.
network
low complexity
apple
6.4
2005-12-31 CVE-2005-3659 Resource Management Errors vulnerability in EMC Legato Networker 7.2/7.2.1/7.2Build172
nsrd.exe in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allows remote attackers to cause a denial of service (nsrd service crash) via a malformed RPC request to RPC program number 390109, which triggers a null dereference.
network
low complexity
emc CWE-399
5.0
2005-12-31 CVE-2005-3658 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in EMC Legato Networker
Multiple heap-based buffer overflows in EMC Legato NetWorker 7.1.x before 7.1.4 and 7.2.x before 7.2.1.Build.314, and other products such as Sun Solstice Backup (SBU) 6.0 and 6.1 and StorEdge Enterprise Backup Software (EBS) 7.1 through 7.2L, allow remote attackers to execute arbitrary code or cause a denial of service (unresponsive application) via malformed RPC packets to (1) RPC program number 390109 (nsrd.exe) and (2) RPC program number 390113 (nsrexecd.exe).
network
low complexity
emc CWE-119
7.5
2005-12-31 CVE-2005-3655 Remote Manager HTTP Request Header Heap Overflow vulnerability in Novell Open Enterprise Server 9
Heap-based buffer overflow in Novell Open Enterprise Server Remote Manager (novell-nrm) in Novell SUSE Linux Enterprise Server 9 allows remote attackers to execute arbitrary code via an HTTP POST request with a negative Content-Length parameter.
network
low complexity
novell
7.5
2005-12-31 CVE-2005-3654 Remote Denial Of Service vulnerability in Blue Coat Systems WinProxy Telnet
Blue Coat Systems Inc.
network
low complexity
bluecoat
7.5