Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-03 CVE-2005-1375 Remote Input Validation vulnerability in Claroline 1.5.3/1.6Beta/1.6Rc1
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to execute arbitrary SQL commands via (1) learningPath.php, (2) learningPathAdmin.php, (3) learnPath_details.php, (4) modules_pool.php, (5) module.php, (6) uInfo parameter in userInfo.php, or (7) exo_id parameter to exercises_details.php.
network
low complexity
claroline
7.5
2005-05-03 CVE-2005-1374 Remote Input Validation vulnerability in Claroline 1.5.3/1.6Beta/1.6Rc1
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow remote attackers to inject arbitrary web script or HTML via (1) exercise_result.php, (2) exercice_submit.php, (3) agenda.php, (4) learningPathList.php, (5) learningPathAdmin.php, (6) learningPath.php, (7) userLog.php, (8) tool parameter to toolaccess_details.php, (9) data parameter to user_access_details.php, or (10) coursePath parameter to myagenda.php.
network
claroline
6.8
2005-05-03 CVE-2005-1373 SQL Injection vulnerability in Dream4 Koobi CMS 4.2.3
Multiple SQL injection vulnerabilities in index.php in Dream4 Koobi CMS 4.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) q or (2) p parameters.
network
low complexity
dream4
7.5
2005-05-03 CVE-2005-1372 Local Privilege Escalation vulnerability in BakBone NetVault NVStatsMngr.EXE
nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.
local
low complexity
bakbone
4.6
2005-05-03 CVE-2005-1371 Local Privilege Escalation vulnerability in Bulletproof FTP Server 2.4.0.31
BPFTPServer service in BulletProof FTP Server 2.4.0.31 does not properly drop privileges before opening files through the Help menu, which allows local users to gain privileges.
local
low complexity
bulletproof
7.2
2005-05-03 CVE-2005-1370 Remote Command Execution vulnerability in HP OpenView Radia Management Portal 1.0/2.0
Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows remote attackers to execute arbitrary commands via unknown vectors.
network
low complexity
hp
7.5
2005-05-03 CVE-2005-1343 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
local
low complexity
apple
7.2
2005-05-03 CVE-2005-0157 Unspecified vulnerability in Smartlist
The confirm add-on in SmartList 3.15 and earlier allows attackers to subscribe arbitrary e-mail addresses by using a valid cookie that specifies an address other than the address for which the cookie was assigned.
network
low complexity
smartlist
7.5
2005-05-03 CVE-2005-0106 Unspecified vulnerability in Ubuntu Linux 5.04
SSLeay.pm in libnet-ssleay-perl before 1.25 uses the /tmp/entropy file for entropy if a source is not set in the EGD_PATH variable, which allows local users to reduce the cryptographic strength of certain operations by modifying the file.
local
low complexity
ubuntu
4.6
2005-05-02 CVE-2005-1369 Unspecified vulnerability in Linux Kernel
The (1) it87 and (2) via686a drivers in I2C for Linux 2.6.x before 2.6.11.8, and 2.6.12 before 2.6.12-rc2, create the sysfs "alarms" file with write permissions, which allows local users to cause a denial of service (CPU consumption) by attempting to write to the file, which does not have an associated store function.
local
low complexity
linux
2.1