Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-05-12 | CVE-2005-1567 | SQL-Injection vulnerability in Directtopics SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter. | 7.5 |
2005-05-12 | CVE-2005-1565 | Information Disclosure vulnerability in Bugzilla Authentication Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history. | 5.0 |
2005-05-12 | CVE-2005-1564 | Remote Security vulnerability in Bugzilla post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product. | 7.5 |
2005-05-12 | CVE-2005-1532 | Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox and Mozilla Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160. | 7.5 |
2005-05-12 | CVE-2005-1531 | Script Manager Security Bypass vulnerability in Mozilla Suite And Firefox Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant." | 7.5 |
2005-05-12 | CVE-2005-0974 | Unspecified vulnerability in Apple mac OS X Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments. | 7.2 |
2005-05-12 | CVE-2005-0973 | Unspecified vulnerability in Apple mac OS X Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments. | 2.1 |
2005-05-12 | CVE-2005-0972 | Unspecified vulnerability in Apple mac OS X and mac OS X Server Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters. | 7.2 |
2005-05-12 | CVE-2005-0971 | Unspecified vulnerability in Apple mac OS X Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments. | 4.6 |
2005-05-12 | CVE-2005-0969 | Unspecified vulnerability in Apple mac OS X Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters. | 4.6 |