Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0144 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-05-02 CVE-2005-0142 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g.
local
low complexity
mozilla
2.1
2005-05-02 CVE-2005-0141 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.
network
high complexity
mozilla
2.6
2005-05-02 CVE-2005-0140 Remote Buffer Overflow vulnerability in Peid 0.92
Buffer overflow in PeID allows attackers to execute arbitrary code via a PE file with an Import Address Table containing a long import library name.
network
low complexity
peid
7.5
2005-05-02 CVE-2005-0137 Unspecified vulnerability in Linux Kernel 2.6.0
Linux kernel 2.6 on Itanium (ia64) architectures allows local users to cause a denial of service via a "missing Itanium syscall table entry."
local
low complexity
linux
2.1
2005-05-02 CVE-2005-0133 Unspecified vulnerability in Clam Anti-Virus Clamav
ClamAV 0.80 and earlier allows remote attackers to cause a denial of service (clamd daemon crash) via a ZIP file with malformed headers.
network
low complexity
clam-anti-virus
5.0
2005-05-02 CVE-2005-0127 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
network
low complexity
apple
5.0
2005-05-02 CVE-2005-0126 Remote Buffer Overflow vulnerability in Apple ColorSync ICC Header
ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.
network
low complexity
apple
7.5
2005-05-02 CVE-2005-0121 Local Security vulnerability in Alexander Siegel Golddig 2.0
Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.
local
low complexity
alexander-siegel
4.6
2005-05-02 CVE-2005-0120 Local Security vulnerability in helvis
helvis 1.8h2_1 and earlier allows local users to delete arbitrary files via the elvprsv setuid program.
local
low complexity
helvis
2.1