Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-09-30 CVE-2005-2660 Unspecified vulnerability in Apachetop
apachetop 0.12.5 and earlier, when running in debug mode, allows local users to create or append to arbitrary files via a symlink attack on atop.debug.
local
low complexity
apachetop
2.1
2005-09-30 CVE-2005-3115 Unspecified vulnerability in Mpeg-Tools
mpeg-tools before 1.5b-r2 creates multiple temporary files insecurely, which allows local users to overwrite arbitrary files via (1) ts.stat, (2) ts.mpg, (3) foobar, (4) blockbar, or (5) foobar[NNN].
local
low complexity
mpeg-tools
2.1
2005-09-30 CVE-2005-2962 Unspecified vulnerability in Ntlmaps
The post-installation script for ntlmaps before 0.9.9 sets world-readable permissions for the configuration file, which allows local users to obtain the username and password.
local
low complexity
ntlmaps
2.1
2005-09-30 CVE-2005-2917 Denial Of Service vulnerability in Squid 2.5.9
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
network
low complexity
squid
5.0
2005-09-30 CVE-2005-3114 Buffer Overflow vulnerability in NateOn Messenger Arbitrary File Download And
Buffer overflow in the ActiveX control for NateOn Messenger (NateonDownloadManager.ocx) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long third argument to the GotNate.Excute method.
network
low complexity
nateon
7.5
2005-09-30 CVE-2005-3113 Buffer Overflow vulnerability in NateOn Messenger Arbitrary File Download And
The ActiveX control for NateOn Messenger (NateonDownloadManager.ocx) allows remote attackers to download and execute arbitrary programs by setting the arguments to the GotNate.Excute method.
network
low complexity
nateon
7.5
2005-09-30 CVE-2005-3112 Unspecified vulnerability in Macromedia Breeze 5
The "reset password" feature in Macromedia Breeze 5.0 stores passwords in plaintext in the database instead of the hash, which allows attackers with access to the database to obtain the passwords.
local
low complexity
macromedia
2.1
2005-09-30 CVE-2005-3111 Unspecified vulnerability in Debian Backupninja 0.8
The handler code for backupninja 0.8 and earlier creates temporary files with predictable filenames, which allows local users to modify arbitrary files via a symlink attack.
local
low complexity
debian
2.1
2005-09-30 CVE-2005-3110 Multiple Security vulnerability in Linux Kernel 2.6.0
Race condition in ebtables netfilter module (ebtables.c) in Linux 2.6, when running on an SMP system that is operating under a heavy load, might allow remote attackers to cause a denial of service (crash) via a series of packets that cause a value to be modified after it has been read but before it has been locked.
network
high complexity
linux
2.6
2005-09-30 CVE-2005-3106 Improper Locking vulnerability in multiple products
Race condition in Linux 2.6, when threads are sharing memory mapping via CLONE_VM (such as linuxthreads and vfork), might allow local users to cause a denial of service (deadlock) by triggering a core dump while waiting for a thread that has just performed an exec.
local
high complexity
linux debian canonical CWE-667
4.7