Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0614 Remote Security vulnerability in phpBB
sessions.php in phpBB 2.0.12 and earlier allows remote attackers to gain administrator privileges via the autologinid value in a cookie.
network
low complexity
phpbb-group
7.5
2005-05-02 CVE-2005-0612 Remote Default Community String vulnerability in Cisco IP/VC Videoconferencing System SNMP
Cisco IP/VC Videoconferencing System 3510, 3520, 3525 and 3530 contain hard-coded default SNMP community strings, which allows remote attackers to gain access, cause a denial of service, and modify configuration.
network
low complexity
cisco
7.5
2005-05-02 CVE-2005-0611 Unspecified vulnerability in Realnetworks Helix Player, Realone Player and Realplayer
Heap-based buffer overflow in RealNetworks RealPlayer 10.5 (6.0.12.1056 and earlier), 10, 8, and RealOne Player V2 and V1, allows remote attackers to execute arbitrary code via .WAV files.
network
high complexity
realnetworks
5.1
2005-05-02 CVE-2005-0607 Remote Security vulnerability in Cubecart
CubeCart 2.0.0 through 2.0.5 allows remote attackers to determine the full path of the server via direct calls without parameters to (1) information.php, (2) language.php, (3) list_docs.php, (4) popular_prod.php, (5) sale.php, (6) subfooter.inc.php, (7) subheader.inc.php, (8) cat_navi.php, or (9) check_sum.php, which reveals the path in a PHP error message.
network
low complexity
devellion
5.0
2005-05-02 CVE-2005-0606 Cross-Site Scripting vulnerability in CubeCart
Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP files, allows remote attackers to inject arbitrary HTML or web script via the (1) cat_id, (2) PHPSESSID, (3) view_doc, (4) product, (5) session, (6) catname, (7) search, or (8) page parameters.
network
devellion
4.3
2005-05-02 CVE-2005-0604 Local Security vulnerability in GFI Languard Network Security Scanner 5.0
lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.
local
low complexity
gfi
4.6
2005-05-02 CVE-2005-0602 Privilege Escalation vulnerability in Info-Zip Unzip 5.50
Unzip 5.51 and earlier does not properly warn the user when extracting setuid or setgid files, which may allow local users to gain privileges.
local
high complexity
info-zip
6.2
2005-05-02 CVE-2005-0601 Remote vulnerability in Cisco Application and Content Networking System
Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, 5.1, or 5.2 use a default password when the setup dialog has not been run, which allows remote attackers to gain access.
network
low complexity
cisco
7.5
2005-05-02 CVE-2005-0599 Remote vulnerability in Cisco Application and Content Networking System
Cisco devices running Application and Content Networking System (ACNS) 4.x, 5.0, or 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (CPU consumption) via malformed IP packets.
network
low complexity
cisco
5.0
2005-05-02 CVE-2005-0597 Remote vulnerability in Cisco Application and Content Networking System
Cisco devices running Application and Content Networking System (ACNS) 5.0 before 5.0.17.6 and 5.1 before 5.1.11.6 allow remote attackers to cause a denial of service (process restart) via a "crafted TCP connection."
network
low complexity
cisco
5.0