Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-10-05 CVE-2005-3150 Remote Format String vulnerability in Weex Log_Flush() Function
Format string vulnerability in the Log_Flush function in Weex 2.6.1.5, 2.6.1, and possibly other versions allows remote FTP servers to execute arbitrary code via format strings in filenames.
network
low complexity
weex
7.5
2005-10-05 CVE-2005-3149 Unspecified vulnerability in UIM
Uim 0.4.x before 0.4.9.1 and 0.5.0 and earlier does not properly handle the LIBUIM_VANILLA environment variable when a suid or sgid application is linked to libuim, such as immodule for Qt, which allows local users to gain privileges.
local
low complexity
uim
4.6
2005-10-05 CVE-2005-3148 Local Security vulnerability in storeBackup
StoreBackup before 1.19 does not properly set the uid and guid for symbolic links (1) that are backed up by storeBackup.pl, or (2) recovered by storeBackupRecover.pl, which could cause files to be restored with incorrect ownership.
local
low complexity
storebackup suse
4.6
2005-10-05 CVE-2005-3147 Information Disclosure vulnerability in storeBackup
StoreBackup before 1.19 creates the backup root with world-readable permissions, which allows local users to obtain sensitive information.
local
low complexity
storebackup suse
2.1
2005-10-05 CVE-2005-3146 StoreBackup before 1.19 allows local users to perform unauthorized operations on arbitrary files via a symlink attack on temporary files.
local
low complexity
storebackup suse
2.1
2005-10-05 CVE-2005-3145 Denial-Of-Service vulnerability in Standards Based Linux Instrumentation Sblim-Sfcb 0.9.1
httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service (resource consumption) by connecting to sblim-sfcb but not sending any data.
network
low complexity
standards-based-linux-instrumentation
5.0
2005-10-05 CVE-2005-3144 Denial Of Service vulnerability in Standards Based Linux Instrumentation Sblim-Sfcb 0.9.1
httpAdapter.c in sblim-sfcb before 0.9.2 allows remote attackers to cause a denial of service via long HTTP headers.
network
low complexity
standards-based-linux-instrumentation
5.0
2005-10-05 CVE-2005-3143 Remote IMAP Denial of Service vulnerability in 4D WebStar
Unspecified vulnerability in the Mailbox Server for 4D WebStar before 5.3.5 allows attackers to cause a denial of service (crash) via IMAP clients on Mac OS X 10.4 Mail 2.
network
low complexity
4d
5.0
2005-10-05 CVE-2005-3142 Remote Heap Overflow vulnerability in Kaspersky Anti-Virus Library CAB Record
Heap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary code via a CAB file with large records after the header.
network
low complexity
kaspersky-lab
critical
10.0
2005-10-05 CVE-2005-3141 Denial-Of-Service vulnerability in Cerulean Studios Trillian 3.0
Cerulean Studios Trillian 3.0 allows remote attackers to cause a denial of service (crash) via a reverse direct connection from a different client, as demonstrated using LICQ.
network
low complexity
cerulean-studios
5.0