Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-02-28 CVE-2005-0608 Denial-Of-Service vulnerability in Webmod 0.47
Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.
network
low complexity
webmod
7.5
2005-02-28 CVE-2004-0945 Denial-Of-Service vulnerability in Mitel 3300 Integrated Communication Platform
The web management interface for Mitel 3300 Integrated Communications Platform (ICP) before 4.2.2.11 allows remote authenticated users to cause a denial of service (resource exhaustion) via a large number of active sessions, which exceeds ICP's maximum.
network
low complexity
mitel
5.0
2005-02-25 CVE-2005-0580 Local Security vulnerability in Cmd5Checkpw 0.20/0.21/0.22
cmd5checkpw, when running setuid, does not properly drop privileges before calling the execvp function, which allows local users to read the poppasswd file.
local
low complexity
krzysztof-dabrowski
2.1
2005-02-25 CVE-2005-0579 Local Security vulnerability in FreeNX
nxagent in FreeNX before 0.2.8 does not properly handle when the XAUTHORITY environment variable is not set, which allows local users to access the X server without X authentication.
local
low complexity
freenx
4.6
2005-02-25 CVE-2005-0107 Unspecified vulnerability in Debian Bsmtpd 2.3
bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.
network
low complexity
debian
7.5
2005-02-24 CVE-2005-0600 Remote vulnerability in Cisco Application and Content Networking System
Cisco devices running Application and Content Networking System (ACNS) 5.0, 5.1 before 5.1.13.7, or 5.2 before 5.2.3.9 allow remote attackers to cause a denial of service (bandwidth consumption) via "crafted IP packets" that are continuously forwarded.
network
low complexity
cisco
5.0
2005-02-24 CVE-2005-0598 Remote vulnerability in Cisco Application and Content Networking System
The RealServer RealSubscriber on Cisco devices running Application and Content Networking System (ACNS) 5.1 allow remote attackers to cause a denial of service (CPU consumption) via malformed packets.
network
low complexity
cisco
5.0
2005-02-24 CVE-2005-0547 Restricted File Access vulnerability in HP-UX FTP Server
Unknown vulnerability in ftpd on HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23 allows remote authenticated users to gain "unauthorized access to files."
local
low complexity
hp
4.6
2005-02-24 CVE-2005-0543 Cross-Site Scripting vulnerability in PHPmyadmin
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web script via (1) the strServer, cfg[BgcolorOne], or strServerChoice parameters in select_server.lib.php, (2) the bg_color or row_no parameters in display_tbl_links.lib.php, the left_font_family parameter in theme_left.css.php, or the right_font_family parameter in theme_right.css.php.
network
phpmyadmin CWE-79
4.3
2005-02-23 CVE-2005-0521 SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows local users to gain privileges.
local
low complexity
sendlink
2.1