Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-12-16 CVE-2005-3253 Wireless Access Points (AP) for (1) Avaya AP-3 through AP-6 2.5 to 2.5.4, and AP-7/AP-8 2.5 and other versions before 3.1, and (2) Proxim AP-600 and AP-2000 before 2.5.5, and Proxim AP-700 and AP-4000 after 2.4.11 and before 3.1, use a static WEP key of "12345", which allows remote attackers to bypass authentication.
network
low complexity
avaya proxim
7.5
2005-12-15 CVE-2005-4274 Denial-Of-Service vulnerability in Businessobjects Webintelligence 6.5
Unspecified vulnerability in Business Objects WebIntelligence 6.5x allows remote attackers to cause a denial of service (user account lock out) via unknown attack vectors related to "authentication mechanisms" and "form input."
network
low complexity
businessobjects
5.0
2005-12-15 CVE-2005-4273 Unspecified vulnerability in IBM AIX 5.3/5.3L
Multiple unspecified vulnerabilities in (1) getShell and (2) getCommand in IBM AIX 5.3 allow local users to append to arbitrary files.
local
low complexity
ibm
2.1
2005-12-15 CVE-2005-4272 Local Buffer Overflow vulnerability in IBM AIX slocal
Multiple buffer overflows in IBM AIX 5.1, 5.2, and 5.3 allow remote attackers to execute arbitrary code via (1) muxatmd and (2) slocal.
network
low complexity
ibm
critical
10.0
2005-12-15 CVE-2005-4271 Local Buffer Overflow vulnerability in IBM AIX 5.3/5.3L
Buffer overflow in the malloc debug system in IBM AIX 5.3 allows local users to execute arbitrary code.
local
low complexity
ibm
7.2
2005-12-15 CVE-2005-4270 Remote Buffer Overflow vulnerability in Watchfire Appscan QA 5.0.134/5.0.609
Buffer overflow in Watchfire AppScan QA 5.0.609 and 5.0.134 allows remote web servers to execute arbitrary code via an HTTP 401 response with a WWW-Authenticate header containing a long Realm field.
network
low complexity
watchfire
7.5
2005-12-15 CVE-2005-4269 Denial-Of-Service vulnerability in Microsoft IE, Windows 2003 Server and Windows XP
mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form.
network
low complexity
microsoft
7.8
2005-12-15 CVE-2005-4268 Buffer Errors vulnerability in GNU Cpio 2.68
Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits.
local
high complexity
gnu CWE-119
3.7
2005-12-15 CVE-2005-4266 Remote Security vulnerability in Mdaemon
WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.
network
low complexity
alt-n
7.5
2005-12-15 CVE-2005-4264 SQL Injection vulnerability in Triangle Solutions PHP Support Tickets 2.0
Multiple SQL injection vulnerabilities in index.php in PHP Support Tickets 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields, and (3) id parameter.
network
low complexity
triangle-solutions
7.5