Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-03 CVE-2005-1435 Unspecified vulnerability in Open Webmail Open Webmail
Open WebMail (OWM) before 2.51 20050430 allows remote authenticated users to execute arbitrary commands via shell metacharacters in a filename.
network
low complexity
open-webmail
7.5
2005-05-03 CVE-2005-1434 Denial-Of-Service vulnerability in OpenView Network Node Manager
Multiple unknown vulnerabilities in OpenView Network Node Manager (OV NNM) 6.2, 6.4, 7.01, and 7.50 allow attackers to cause a denial of service or execute arbitrary code.
network
low complexity
hp
7.5
2005-05-03 CVE-2005-1433 Denial-Of-Service vulnerability in OpenView Event Correlation Services 3.2/3.3
Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.
local
low complexity
hp
4.6
2005-05-03 CVE-2005-1431 Denial of Service vulnerability in GNUTLS Padding
The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.
network
low complexity
gnu
5.0
2005-05-03 CVE-2005-1430 Local Security vulnerability in Mac OS X
Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.
local
low complexity
apple
3.6
2005-05-03 CVE-2005-1429 SQL Injection vulnerability in Abczone.It Wwwguestbook 1.1
SQL injection vulnerability in login.asp in WWWguestbook 1.1 allows remote attackers to execute arbitrary SQL commands via the password parameter.
network
low complexity
abczone-it
7.5
2005-05-03 CVE-2005-1428 File-Upload vulnerability in Uapplication Uphotogallery
edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.
network
low complexity
uapplication
7.5
2005-05-03 CVE-2005-1427 Information Disclosure vulnerability in uPhotoGallery
Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.
network
low complexity
uapplication
7.5
2005-05-03 CVE-2005-1426 Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/blog.mdb (aka mdb-database/blog.msb).
network
low complexity
uapplication CWE-264
5.0
2005-05-03 CVE-2005-1425 Permissions, Privileges, and Access Controls vulnerability in Uapplication Uguestbook 1.0
Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for mdb-database/guestbook.mdb.
network
low complexity
uapplication CWE-264
5.0