Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-06-08 CVE-2005-1968 Cross-Site Scripting vulnerability in Early Impact Productcart 2.7
Cross-site scripting (XSS) vulnerability in ProductCart Ecommerce before 2.7 allows remote attackers to inject arbitrary web script or HTML via the error parameter to techErr.asp.
network
early-impact
4.3
2005-06-08 CVE-2005-1960 The getemails function in C.J.
network
low complexity
c-j-steele
7.5
2005-06-08 CVE-2005-1943 SQL Injection vulnerability in Loki Download Manager Default.ASP
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.
network
low complexity
loki
7.5
2005-06-08 CVE-2005-1941 Incorrect Default Permissions vulnerability in Silvercity Project Silvercity
SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.
local
low complexity
silvercity-project CWE-276
7.8
2005-06-08 CVE-2005-1758 Remote vulnerability in Novell NetMail
Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.
network
low complexity
novell
7.5
2005-06-08 CVE-2005-1757 Remote vulnerability in Novell NetMail
Buffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.
network
low complexity
novell
7.5
2005-06-08 CVE-2005-1756 Remote vulnerability in Novell NetMail
Cross-site scripting (XSS) vulnerability in the ModWeb agent for Novell NetMail 3.52 before 3.52C allows remote attackers to inject arbitrary web script or HTML via calendar display fields.
network
novell
4.3
2005-06-08 CVE-2005-1728 Unspecified vulnerability in Apple mac OS X 10.4/10.4.1
MCX Client for Apple Mac OS X 10.4.x up to 10.4.1 insecurely logs Portable Home Directory credentials, which allows local users to obtain the credentials.
local
low complexity
apple
4.6
2005-06-08 CVE-2005-1727 Unspecified vulnerability in Apple mac OS X Server 10.4/10.4.1
Apple Mac OS X 10.4.x up to 10.4.1 sets insecure world- and group-writable permissions for the (1) system cache folder and (2) Dashboard system widgets, which allows local users to conduct unauthorized file operations via "file race conditions."
local
high complexity
apple
3.7
2005-06-08 CVE-2005-1725 Unspecified vulnerability in Apple mac OS X Server 10.4/10.4.1
launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack on the socket file in an insecure temporary directory.
local
low complexity
apple
2.1