Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-08-10 CVE-2005-1984 Buffer Overflow vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.
network
low complexity
microsoft
7.5
2005-08-10 CVE-2005-1983 Buffer Overflow vulnerability in Microsoft Windows 2000 and Windows XP
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.
network
low complexity
microsoft
critical
10.0
2005-08-10 CVE-2005-1982 Man In The Middle vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
local
low complexity
microsoft
3.6
2005-08-10 CVE-2005-1981 Unspecified vulnerability in Microsoft Windows 2000 and Windows 2003 Server
Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.
local
low complexity
microsoft
2.1
2005-08-10 CVE-2005-1218 Remote Desktop Protocol Denial Of Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.
network
low complexity
microsoft
5.0
2005-08-10 CVE-2005-0058 Buffer Overflow vulnerability in Microsoft Windows Telephony Service
Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to elevate privileges or execute arbitrary code via a crafted message.
network
low complexity
microsoft
7.5
2005-08-07 CVE-2005-2489 Unspecified vulnerability in web Content Management web Content Management News System
Web Content Management News System allows remote attackers to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.
network
low complexity
web-content-management
7.5
2005-08-07 CVE-2005-2488 Cross-Site Scripting vulnerability in Web Content Management
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote attackers to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
4.3
2005-08-07 CVE-2005-2487 Remote Denial Of Service vulnerability in McDATA E/OS
Unknown vulnerability in Sun McData switches and directors 4300, 4500, 6064, and 6140 before E/OS 6.0.0 may allow attackers to cause a denial of service (connectivity and array access loss) via a network broadcast storm.
local
low complexity
mcdata
2.1
2005-08-07 CVE-2005-2486 SQL Injection vulnerability in Portailphp 2.4
SQL injection vulnerability in mod_forum/read_message.php in PortailPHP allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php with the affiche parameter set to "Forum-read_mess", a different vulnerability than CVE-2005-1701.
network
low complexity
portailphp
7.5