Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-14 CVE-2005-1548 SQL Injection vulnerability in Advanced Guestbook Advanced Guestbook 2.3.1
SQL injection vulnerability in index.php in Advanced Guestbook 2.3.1 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
network
low complexity
advanced-guestbook
7.5
2005-05-14 CVE-2005-1547 Remote Security vulnerability in Bakbone Netvault 7.3
Heap-based buffer overflow in the demo version of Bakbone Netvault, and possibly other versions, allows remote attackers to execute arbitrary commands via a large packet to port 20031.
network
low complexity
bakbone
7.5
2005-05-14 CVE-2005-1546 Unspecified vulnerability in HT Editor HT Editor
Buffer overflow in the PE parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted PE file.
network
high complexity
ht-editor
5.1
2005-05-14 CVE-2005-1545 Unspecified vulnerability in HT Editor HT Editor
Integer overflow in the ELF parser in HT Editor before 0.8.0 allows remote attackers to execute arbitrary code via a crafted ELF file, which leads to a heap-based buffer overflow.
network
high complexity
ht-editor
5.1
2005-05-14 CVE-2005-1544 Buffer Overflow vulnerability in LibTIFF TIFFOpen
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.
network
low complexity
libtiff
7.5
2005-05-13 CVE-2005-1578 Local Security vulnerability in Guidance Software Encase 4.18A
EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide information without detection.
local
low complexity
guidance-software
2.1
2005-05-13 CVE-2005-0758 zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
local
low complexity
gnu canonical
4.6
2005-05-12 CVE-2005-1579 Information Disclosure vulnerability in Apple Quicktime 7.0
Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.
network
low complexity
apple
5.0
2005-05-12 CVE-2005-1576 Remote Security vulnerability in Mozilla Firefox 0.10.1/1.0
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.
network
high complexity
mozilla
2.6
2005-05-12 CVE-2005-1568 Information Disclosure vulnerability in Directtopics
topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to obtain sensitive information via an invalid topic parameter, which reveals the path in an error message.
network
low complexity
directtopics
5.0