Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-10-27 CVE-2005-3265 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Skype Technologies Skype
Buffer overflow in Skype for Windows 1.1.x.0 through 1.4.x.83 allows remote attackers to execute arbitrary code via (1) callto:// and (2) skype:// links, or (3) a non-standard VCARD, possibly due to an underlying error in the SysUtils.WideFmtStr Delphi routine.
network
skype-technologies CWE-119
critical
9.3
2005-10-27 CVE-2005-3088 Information Exposure vulnerability in Fetchmail 6.2.0/6.2.5/6.2.5.2
fetchmailconf before 1.49 in fetchmail 6.2.0, 6.2.5 and 6.2.5.2 creates configuration files with insecure world-readable permissions, which allows local users to obtain sensitive information such as passwords.
local
low complexity
fetchmail CWE-200
2.1
2005-10-27 CVE-2005-2338 HTML Injection vulnerability in XOOPS
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in the forum module.
network
xoops
4.3
2005-10-26 CVE-2005-3312 Unspecified vulnerability in Microsoft Internet Explorer 6.0
The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on the link, even though the web server response and file extension indicate that it should be treated as a different file type.
network
microsoft
4.3
2005-10-26 CVE-2005-3311 Unspecified vulnerability in BMC Software Control-M Agent 6.1.03
BMC Software Control-M 6.1.03 for Solaris, and possibly other platforms, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
local
low complexity
bmc
2.1
2005-10-26 CVE-2005-3310 HTML Injection vulnerability in PHPbb Group PHPbb 2.0.17
Interpretation conflict in phpBB 2.0.17, with remote avatars and avatar uploading enabled, allows remote authenticated users to inject arbitrary web script or HTML via an HTML file with a GIF or JPEG file extension, which causes the HTML to be executed by a victim who views the file in Internet Explorer, which renders malformed image types as HTML, enabling cross-site scripting (XSS) attacks.
network
phpbb-group
3.5
2005-10-26 CVE-2005-3309 SQL-Injection vulnerability in Zomplog 3.4
Multiple SQL injection vulnerabilities in Zomplog 3.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in detail.php and the catid parameter in (2) get.php and (3) index.php.
network
low complexity
zomplog
7.5
2005-10-26 CVE-2005-3308 HTML Injection vulnerability in Zomplog 3.3/3.4
Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) comment parameter in detail.php, (3) the username parameter in get.php, and (4) the search parameter in index.php.
network
zomplog
4.3
2005-10-26 CVE-2005-3307 Remote File Include vulnerability in FlatNuke
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale parameter in a newtopic operation.
network
low complexity
flatnuke
5.0
2005-10-26 CVE-2005-3306 Unspecified vulnerability in Flatnuke 2.5.6
Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vulnerability than CVE-2005-2814.
network
flatnuke
4.3