Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-1755 Remote Security vulnerability in PHP Poll Creator PHP Poll Creator 1.01
PHP remote file inclusion vulnerability in poll_vote.php in PHP Poll Creator 1.01 allows remote attackers to execute arbitrary PHP code via the relativer_pfad parameter.
network
low complexity
php-poll-creator
6.4
2005-12-31 CVE-2005-1752 Remote Arbitrary Command Execution vulnerability in GForge
viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter.
network
low complexity
gforge
6.4
2005-12-31 CVE-2005-1730 Unspecified vulnerability in Novell Imanager 1.5/2.0/2.0.2
Multiple vulnerabilities in the OpenSSL ASN.1 parser, as used in Novell iManager 2.0.2, allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted packets, as demonstrated by "OpenSSL ASN.1 brute forcer." NOTE: this issue might overlap CVE-2004-0079, CVE-2004-0081, or CVE-2004-0112.
network
novell
critical
9.3
2005-12-31 CVE-2005-1726 Multiple vulnerability in Apple mac OS X 10.4.1
The CoreGraphics Window Server in Mac OS X 10.4.1 allows local users with console access to gain privileges by "launching commands into root sessions."
local
low complexity
apple
4.6
2005-12-31 CVE-2005-1528 Local Privilege Escalation and Denial Of Service vulnerability in QNX Rtos 6.2.1
Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library.
local
low complexity
qnx
7.2
2005-12-31 CVE-2005-0985 Denial-Of-Service vulnerability in Apple Mac OS X
Unspecified vulnerability in the Mac OS X kernel before 10.3.8 allows local users to cause a denial of service (temporary hang) via unspecified attack vectors related to the fan control unit (FCU) driver.
local
low complexity
apple
2.1
2005-12-31 CVE-2005-0489 Local Denial of Service vulnerability in Linux Kernel Invalid Proc Memory Access
The /proc handling (proc/base.c) Linux kernel 2.4 before 2.4.17 allows local users to cause a denial of service via unknown vectors that cause an invalid access of free memory.
local
low complexity
linux
4.9
2005-12-31 CVE-2005-0136 Unspecified vulnerability in Linux Kernel
The Linux kernel before 2.6.11 on the Itanium IA64 platform has certain "ptrace corner cases" that allow local users to cause a denial of service (crash) via crafted syscalls, possibly related to MCA/INIT, a different vulnerability than CVE-2005-1761.
local
low complexity
linux
2.1
2005-12-31 CVE-2005-0038 Remote Denial of Service vulnerability in Multiple Vendor DNS Message Decompression
The DNS implementation of PowerDNS 2.9.16 and earlier allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.
network
low complexity
powerdns
5.0
2005-12-31 CVE-2005-0037 Remote Denial of Service vulnerability in Multiple Vendor DNS Message Decompression
The DNS implementation of DNRD before 2.10 allows remote attackers to cause a denial of service via a compressed DNS packet with a label length byte with an incorrect offset, which could trigger an infinite loop.
network
low complexity
dnrd
5.0