Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-07-05 CVE-2005-1922 Unspecified vulnerability in Clam Anti-Virus Clamav
The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function.
network
low complexity
clam-anti-virus
5.0
2005-07-05 CVE-2005-1917 Unspecified vulnerability in Kpopper 1.0
kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.
local
low complexity
kpopper
2.1
2005-07-05 CVE-2005-1625 Unspecified vulnerability in Adobe Acrobat Reader 5.0.10/5.0.9
Stack-based buffer overflow in the UnixAppOpenFilePerform function in Adobe Reader 5.0.9 and 5.0.10 for Unix allows remote attackers to execute arbitrary code via a PDF document with a long /Filespec tag.
network
low complexity
adobe
5.0
2005-07-05 CVE-2005-0393 Unspecified vulnerability in Crip 3.5
The helper scripts for crip 3.5 do not properly use temporary files, which allows local users to have an unknown impact with unknown attack vectors.
local
low complexity
crip
7.2
2005-07-05 CVE-2005-0360 Remote Security vulnerability in Log Sink Class Activex Control
The Microsoft Log Sink Class ActiveX control in pkmcore.dll is marked as "safe for scripting" for Internet Explorer, which allows remote attackers to create or append to arbitrary files.
network
low complexity
microsoft
5.0
2005-06-30 CVE-2005-2069 Cleartext Transmission of Sensitive Information vulnerability in Padl NSS Ldap and PAM Ldap
pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is referred to a master, which may cause a password to be sent in cleartext and allows remote attackers to sniff the password.
network
low complexity
padl CWE-319
5.0
2005-06-29 CVE-2005-2080 Remote Agent for Windows Servers Privilege Escalation vulnerability in Veritas Backup Exec
Unknown vulnerability in Remote Agent for Windows Servers (RAWS) in VERITAS Backup Exec 9.0 through 10.0 for Windows, and 9.0.4019 through 9.1.307 for NetWare, allows remote attackers to gain privileges by copying the handle for the server.
network
low complexity
symantec-veritas
7.5
2005-06-29 CVE-2005-2078 Remote Denial Of Service vulnerability in Sofotex Bisonftp V4R1
BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.
local
low complexity
sofotex
2.1
2005-06-29 CVE-2005-2077 Cross-Site Scripting vulnerability in Hosting Controller Error.ASP
Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.
4.3
2005-06-29 CVE-2005-2076 Unspecified vulnerability in HP Version Control Repository Manager
HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.
local
low complexity
hp
2.1