Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-07-11 CVE-2005-2182 Improper Verification of Cryptographic Signature vulnerability in Grandstream Bt-100 Firmware
Grandstream BudgeTone (BT) 100 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.
network
low complexity
grandstream CWE-347
7.5
2005-07-11 CVE-2005-2181 Improper Verification of Cryptographic Signature vulnerability in Cisco IP Phone 7940 Firmware and IP Phone 7960 Firmware
Cisco 7940/7960 Voice over IP (VoIP) phones do not properly check the Call-ID, branch, and tag values in a NOTIFY message to verify a subscription, which allows remote attackers to spoof messages such as the "Messages waiting" message.
network
low complexity
cisco CWE-347
7.5
2005-07-11 CVE-2005-2180 Local Security vulnerability in Gnats 4.0/4.1.0
gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.
local
low complexity
gnu
2.1
2005-07-11 CVE-2005-2179 Remote Security vulnerability in JAWS
PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.
network
low complexity
jaws
5.0
2005-07-11 CVE-2005-2178 Remote Security vulnerability in Probe.Cgi
probe.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the olddat parameter.
network
low complexity
probe-cgi
7.5
2005-07-11 CVE-2005-2177 Improper Input Validation vulnerability in Net-Snmp
Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.
network
low complexity
net-snmp CWE-20
5.0
2005-07-11 CVE-2005-2170 Remote Denial Of Service vulnerability in IBM Tivoli Management Framework 4.1.1
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.
network
low complexity
ibm
5.0
2005-07-11 CVE-2005-2150 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.
network
low complexity
microsoft
5.0
2005-07-11 CVE-2005-1848 Unspecified vulnerability in Phystech Dhcpcd 1.3.17Pl2
The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.
network
low complexity
phystech
5.0
2005-07-11 CVE-2005-1768 Local Buffer Overflow vulnerability in Linux Kernel IA32 ExecVE
Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that increments a pointer count after the nargs function has counted the pointers, but before the count is copied from user space to kernel space, which leads to a buffer overflow.
local
high complexity
linux
3.7