Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-10-04 CVE-2005-3135 Buffer Overflow vulnerability in Virtools Web Player
Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a long filename.
network
low complexity
virtools
7.5
2005-10-04 CVE-2005-3133 Directory Traversal vulnerability in IceWarp Web Mail
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary files or directories via a relative path to the id parameter to logout.html or (2) include arbitrary PHP files or other files via the helpid parameter to help.html.
network
low complexity
icewarp merak
5.0
2005-10-04 CVE-2005-3132 Information Disclosure vulnerability in Web Mail
MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct request to bwlist_inc.html, which reveals the path in an error message.
network
low complexity
icewarp merak
5.0
2005-10-04 CVE-2005-3131 Cross-Site Scripting vulnerability in IceWarp
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to blank.html, or the createdataCX parameter to (2) calendar_d.html, (3) calendar_m.html, or (4) calendar_w.html.
network
icewarp merak
4.3
2005-10-04 CVE-2005-3130 SQL Injection vulnerability in Lucidcms 1.0.11
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login field.
network
low complexity
lucidcms
7.5
2005-10-04 CVE-2005-3129 Cross-Site Request Forgery vulnerability in Serendipity
Cross-site request forgery (CSRF) vulnerability in Serendipity 0.8.4 and earlier allows remote attackers to perform unauthorized actions as a logged in user via a link or IMG tag to serendipity_admin.php.
network
high complexity
s9y
5.1
2005-10-04 CVE-2005-3128 Cross-Site Scripting vulnerability in SquirrelMail Address Add Plugin 1.9/2.0
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote attackers to inject arbitrary web script or HTML via the IMG tag.
network
squirrelmail
4.3
2005-10-04 CVE-2005-3127 Cross-Site Scripting vulnerability in Lucidcms 1.0.11
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web script or HTML via the query string.
network
lucidcms
4.3
2005-10-04 CVE-2005-2804 Local Integer Overflow vulnerability in Novell Groupwise 6.5.3
Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers to cause a denial of service (application crash) via a large TCP/IP port in the Windows registry key.
network
low complexity
novell
5.0
2005-09-30 CVE-2005-3060 Local Buffer Overflow vulnerability in IBM AIX Getconf
Buffer overflow in getconf in IBM AIX 5.2 to 5.3 allows local users to execute arbitrary code via unknown vectors.
local
low complexity
ibm
7.2