Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-07-09 CVE-2005-2176 Unspecified vulnerability in Novell Netmail
Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
network
low complexity
novell
6.4
2005-07-09 CVE-2005-2175 Remote Security vulnerability in Lotus Notes
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
network
low complexity
ibm
5.0
2005-07-08 CVE-2005-2174 Unspecified vulnerability in Mozilla Bugzilla
Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.
network
high complexity
mozilla
2.6
2005-07-08 CVE-2005-2173 Unspecified vulnerability in Mozilla Bugzilla
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.
network
low complexity
mozilla
5.0
2005-07-07 CVE-2005-1841 Unspecified vulnerability in Adobe Acrobat Reader 5.0.10/5.0.9
The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.
local
low complexity
adobe
2.1
2005-07-06 CVE-2005-2169 Directory Traversal vulnerability in KAF Oseo Quick and Dirty PHPsource Printer 1.1
Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences.
network
low complexity
kaf-oseo
5.0
2005-07-06 CVE-2005-2165 Remote Security vulnerability in GlobalNoteScript
read.cgi in GlobalNoteScript allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameters.
network
low complexity
globalnotescript
7.5
2005-07-06 CVE-2005-2164 SQL-Injection vulnerability in Covide Groupware-Crm Covide 5.2
SQL injection vulnerability in Covide Groupware-CRM allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.
network
low complexity
covide-groupware-crm
7.5
2005-07-06 CVE-2005-2163 Cross-Site Scripting vulnerability in Autoindex PHP Script 1.5.2
Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
network
autoindex
4.3
2005-07-06 CVE-2005-2162 Remote Security vulnerability in Levcgi.Com Myguestbook 0.6.1
PHP remote file inclusion vulnerability in form.inc.php3 in MyGuestbook 0.6.1 allows remote attackers to execute arbitrary PHP code via the lang parameter.
network
low complexity
levcgi-com
5.0