Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-04-25 CVE-2005-1295 Remote Security vulnerability in Include.Cgi
include.cgi script allows remote attackers to read arbitrary files via a full pathname in the argument.
network
low complexity
include-cgi
7.5
2005-04-25 CVE-2005-1275 Remote Buffer Overflow vulnerability in ImageMagick PNM Image Decoding
Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.
network
low complexity
graphicsmagick imagemagick
5.0
2005-04-25 CVE-2005-0684 Remote Buffer Overflow vulnerability in MySQL MaxDB HTTP GET Request
Multiple buffer overflows in the web tool for MySQL MaxDB before 7.5.00.26 allows remote attackers to execute arbitrary code via (1) an HTTP GET request with a long file parameter after a percent ("%") sign or (2) a long Lock-Token string to the WebDAV functionality, which is not properly handled by the getLockTokenHeader function in WDVHandler_CommonUtils.c.
network
low complexity
mysql
critical
10.0
2005-04-24 CVE-2005-1312 Remote File Include vulnerability in Yappa-NG
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.
network
low complexity
yappa-ng
7.5
2005-04-24 CVE-2005-1303 Remote Security vulnerability in Citat.Pl
The citat.pl script allows remote attackers to read arbitrary files via a full pathname in the argument.
network
low complexity
citat-pl
7.5
2005-04-24 CVE-2005-1294 Local Security vulnerability in Affix
The affix_sock_register in the Affix Bluetooth Protocol Stack for Linux might allow local users to gain privileges via a socket call with a negative protocol value, which is used as an array index.
local
low complexity
nokia
7.2
2005-04-24 CVE-2005-1246 Denial-Of-Service vulnerability in Snmppd
Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format string specifiers that are not properly handled in a syslog call.
network
low complexity
vladislav-bogdanov
critical
10.0
2005-04-23 CVE-2005-1310 SQL-Injection vulnerability in Eaden Mckee Bblog 0.7.4
SQL injection vulnerability in bBlog 0.7.4 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
network
low complexity
eaden-mckee
7.5
2005-04-23 CVE-2005-1291 SQL-Injection vulnerability in Asp Cart
Multiple SQL injection vulnerabilities in CartWIZ ASP Cart allow remote attackers to execute arbitrary SQL commands via the idProduct parameter to (1) addToCart.asp or (2) productDetails.asp, the (3) priceFrom, (4) idCategory, or (5) priceTo parameter to searchResults.asp, or (6) the idParentCategory parameter to productCatalogSubCats.asp.
network
low complexity
cartwiz
7.5
2005-04-23 CVE-2005-1287 SQL-Injection vulnerability in Bk Forum
Multiple SQL injection vulnerabilities in BK Forum 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to member.asp, (2) forum parameter to forum.asp, or (3) various parameters in register.asp.
network
low complexity
bk-dev
7.5