Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0829 Unspecified vulnerability in PHP Fusion PHP Fusion 5.01
Cross-site scripting (XSS) vulnerability in setuser.php of the Digitanium addon to PHP-Fusion 5.01 allows remote attackers to inject arbitrary web script or HTML via the (1) user_name or (2) user_pass parameters.
network
php-fusion
4.3
2005-05-02 CVE-2005-0826 Denial Of Service vulnerability in OllyDbg Library Module Name
OllyDbg 1.10 and earlier allows remote attackers to cause a denial of service (application crash) via a dynamic link library (DLL) with a long filename.
network
low complexity
ollydbg
5.0
2005-05-02 CVE-2005-0825 Unspecified vulnerability in Lgames Ltris 1.0.9
Buffer overflow in LTris before 1.0.10 allows local users to execute arbitrary code via a crafted highscores file.
network
low complexity
lgames
7.5
2005-05-02 CVE-2005-0824 Link Following vulnerability in Mathopd
The internal_dump function in Mathopd before 1.5p5, and 1.6x before 1.6b6 BETA, when Mathopd is running with the -n option, allows local users to overwrite arbitrary files via a symlink attack on dump files that are triggered by a SIGWINCH signal.
local
low complexity
mathopd CWE-59
5.5
2005-05-02 CVE-2005-0823 Local Credential Storage vulnerability in Thepoolclub Ipool and Isnooker
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.txt file, which allows local users to gain privileges.
local
low complexity
thepoolclub
4.6
2005-05-02 CVE-2005-0822 Information Disclosure vulnerability in Citrix Metaframe Password Manager 2.5
Citrix Metaframe Password Manager 2.5 and earlier stores a password in cleartext although it is obfuscated when presented to a user, which allows users to view their secondary passwords even if it is not allowed by policy.
local
low complexity
citrix
2.1
2005-05-02 CVE-2005-0821 Multiple vulnerability in Citrix MetaFrame
Unknown vulnerability in Citrix MetaFrame Conferencing Manager 3.0 allows conference members to bypass organizer restrictions to control the keyboard and mouse.
network
low complexity
citrix
7.5
2005-05-02 CVE-2005-0820 Microsoft Office InfoPath 2003 SP1 includes sensitive information in the Manifest.xsf file in a custom .xsn form, which allows attackers to obtain printer and network information, obtain the database name, username, and password, or obtain the internal web server name.
network
low complexity
microsoft
5.0
2005-05-02 CVE-2005-0819 Unspecified vulnerability in Novell Netware 6.5
The xvesa code in Novell Netware 6.5 SP2 and SP3 allows remote attackers to redirect the xsession without authentication via a direct request to GUIMirror/Start.
network
low complexity
novell
5.0
2005-05-02 CVE-2005-0818 Unspecified vulnerability in Punbb 1.2.3
Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) email or (2) Jabber parameters.
network
punbb
4.3