Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-02-11 CVE-2005-0114 Local Denial of Service vulnerability in Zone Labs ZoneAlarm
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.
local
low complexity
checkpoint zonelabs
2.1
2005-02-11 CVE-2005-0074 Local Buffer Overflow vulnerability in Xpcd 2.08
Buffer overflow in pcdsvgaview in xpcd 2.08 allows local users to execute arbitrary code.
local
low complexity
xpcd
7.2
2005-02-10 CVE-2005-0364 Denial-Of-Service vulnerability in HP Hp-Ux 11.00/11.11/11.23
Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.
network
low complexity
hp
5.0
2005-02-10 CVE-2005-0261 Local File Disclosure vulnerability in IBM AIX LSPath Unauthorized
lspath in AIX 5.2, 5.3, and possibly earlier versions, does not drop privileges before processing the -f option, which allows local users to read one line of arbitrary files.
local
low complexity
ibm
2.1
2005-02-09 CVE-2005-0367 File-Upload vulnerability in Argosoft Mail Server 1.8.7.3
Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a ..
local
low complexity
argosoft
4.6
2005-02-09 CVE-2005-0362 Local Security vulnerability in AWStats
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.
local
low complexity
awstats
4.6
2005-02-09 CVE-2004-0982 Remote URL Open Buffer Overflow vulnerability in Mpg123 0.59R/Pre0.59S
Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 file that contains a long string before the @ (at sign) in a URL.
network
low complexity
mpg123
critical
10.0
2005-02-09 CVE-2004-0981 Buffer overflow in the EXIF parsing routine in ImageMagick before 6.1.0 allows remote attackers to execute arbitrary code via a certain image file.
network
low complexity
imagemagick debian gentoo suse
critical
10.0
2005-02-09 CVE-2004-0980 Remote Format String vulnerability in EZ-IPupdate
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
network
low complexity
angus-mackay debian gentoo
critical
10.0
2005-02-09 CVE-2004-0978 Out-Of-Bounds Write vulnerability in Microsoft Internet Explorer 5.01/5.5/6
Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter.
network
low complexity
microsoft CWE-787
critical
10.0