Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-1168 Unspecified vulnerability in Musicmatch Jukebox 9.0.5059
DiagCollectionControl.dll in Musicmatch 10.00.2047 and earlier allows remote attackers to overwrite arbitrary files via the bstrSavePath argument.
network
low complexity
musicmatch
5.0
2005-05-02 CVE-2005-1167 Information Disclosure vulnerability in Jukebox
Musicmatch 10.00.2047 and earlier store log files in the Program Files directory instead of the user profile, which may allow local users to obtain sensitive information.
local
low complexity
musicmatch
2.1
2005-05-02 CVE-2005-1166 Unspecified vulnerability in Dameware Development Dameware NT Utilities and Miniremote Control
The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain sensitive information.
local
low complexity
dameware-development
2.1
2005-05-02 CVE-2005-1165 Yager 5.24 and earlier allows remote attackers to cause a denial of service (application crash) via certain malformed data.
network
low complexity
yager-development
5.0
2005-05-02 CVE-2005-1164 Denial Of Service vulnerability in Yager Development Yager Game 5.0/5.20/5.24
Yager 5.24 and earlier allows remote attackers to cause a denial of service (application hang) via a packet with a game header that provides less data than indicated by the length.
network
low complexity
yager-development
5.0
2005-05-02 CVE-2005-1163 Buffer Overflow vulnerability in Yager Development Yager Game 5.0/5.20/5.24
Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted nickname or (2) a packet with a large amount of data.
network
low complexity
yager-development
6.4
2005-05-02 CVE-2005-1160 Unspecified vulnerability in Mozilla Firefox and Mozilla
The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.
network
high complexity
mozilla
5.1
2005-05-02 CVE-2005-1159 Unspecified vulnerability in Mozilla Firefox and Mozilla
The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.
network
low complexity
mozilla
7.5
2005-05-02 CVE-2005-1158 Unspecified vulnerability in Mozilla Firefox
Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.
network
low complexity
mozilla
5.0
2005-05-02 CVE-2005-1157 Remote Script Code Execution vulnerability in Mozilla Suite And Firefox Search Plug-In
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones using sidebar.addSearchEngine and the same filename as the target engine, which may not be displayed in the GUI, which could then be used to execute malicious script, aka "Firesearching 2."
network
low complexity
mozilla netscape
7.5