Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-01-13 CVE-2005-0381 Cross-Site Scripting vulnerability in Forumkit 1.0
Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.
network
forumkit
4.3
2005-01-13 CVE-2005-0111 Remote Buffer Overflow vulnerability in Mysql Maxdb 7.5.00
Stack-based buffer overflow in the websql CGI program in MySQL MaxDB 7.5.00 allows remote attackers to execute arbitrary code via a long password parameter.
network
low complexity
mysql
7.5
2005-01-13 CVE-2005-0069 Unspecified vulnerability in VIM Development Group VIM
The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.
local
low complexity
vim-development-group
4.6
2005-01-12 CVE-2005-0456 Unspecified vulnerability in Opera Browser
Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.
network
low complexity
opera
5.0
2005-01-12 CVE-2005-0376 Remote Security vulnerability in Sergey Kiselev Sgallery 1.01
PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.
network
low complexity
sergey-kiselev
7.5
2005-01-11 CVE-2005-0288 Unspecified vulnerability in Bottomline Webseries Payment Application 4.0
The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.
local
low complexity
bottomline
3.6
2005-01-11 CVE-2005-0117 Local Security vulnerability in XShisen
Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.
local
low complexity
xshisen
4.6
2005-01-11 CVE-2005-0108 Integer Overflow vulnerability in Apache MOD Auth Radius 1.5.4
Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.
network
low complexity
apache
5.0
2005-01-11 CVE-2005-0097 Remote Denial of Service vulnerability in Squid Proxy Malformed NTLM Type 3 Message
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.
network
low complexity
squid
5.0
2005-01-11 CVE-2004-1039 Denial of Service vulnerability in SCO UnixWare NFS Mountd
The NFS mountd service on SCO UnixWare 7.1.1, 7.1.3, 7.1.4, and 7.0.1, and possibly other versions, when run from inetd, allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests, which causes inetd to launch a separate process for each request.
network
low complexity
sco
5.0