Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-10-14 CVE-2005-3239 Denial Of Service vulnerability in Clam Anti-Virus Clamav .
The OLE2 unpacker in clamd in Clam AntiVirus (ClamAV) 0.87-1 allows remote attackers to cause a denial of service (segmentation fault) via a DOC file with an invalid property tree, which triggers an infinite recursion in the ole2_walk_property_tree function.
network
low complexity
clam-anti-virus
7.8
2005-10-14 CVE-2005-3238 Denial-Of-Service vulnerability in Sun Solaris
Multiple unspecified vulnerabilities in Solaris 10 SCTP Socket Option Processing allows local users to cause a denial of service (panic) via unspecified attack vectors.
local
low complexity
sun
2.1
2005-10-14 CVE-2005-3237 Input Validation vulnerability in Cyphor
Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote attackers to inject arbitrary web script or HTML via the t_login parameter of footer.php.
network
cynox
4.3
2005-10-14 CVE-2005-3236 Input Validation vulnerability in Cynox Cyphor 0.19
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain administrative access via (1) the fid parameter of newmsg.php, which can enable XSS attacks when the SQL syntax is invalid or (2) the nick parameter of lostpwd.php.
network
cynox
6.8
2005-10-14 CVE-2005-3235 Security Bypass vulnerability in Proland Protector Plus 2000
Multiple interpretation error in unspecified versions of Proland Protector Plus 2000 Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
network
high complexity
proland
5.1
2005-10-14 CVE-2005-3234 Security Bypass vulnerability in Avg Antivirus
Multiple interpretation error in unspecified versions of Grisoft AVG Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
network
high complexity
grisoft
5.1
2005-10-14 CVE-2005-3233 Security Bypass vulnerability in Antivirus
Multiple interpretation error in unspecified versions of Trustix Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
network
high complexity
trustix
5.1
2005-10-14 CVE-2005-3232 Security Bypass vulnerability in Thehacker
Multiple interpretation error in unspecified versions of TheHacker allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
network
high complexity
thehacker
5.1
2005-10-14 CVE-2005-3231 Security Bypass vulnerability in Quick Heal
Multiple interpretation error in unspecified versions of CAT Quick Heal allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
network
high complexity
cat
5.1
2005-10-14 CVE-2005-3230 Security Bypass vulnerability in Panda Antivirus
Multiple interpretation error in unspecified versions of Panda Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are rejected as corrupted by Winzip and BitZipper.
network
high complexity
panda
5.1