Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-07-05 CVE-2005-2146 Local Security vulnerability in SSH Tectia Server 4.3.1
SSH Tectia Server 4.3.1 and earlier, and SSH Secure Shell for Windows Servers, uses insecure permissions when generating the Secure Shell host identification key, which allows local users to access the key and spoof the server.
local
low complexity
ssh
4.6
2005-07-05 CVE-2005-2145 Local Security vulnerability in Prevx PRO 2005 1.0
The kernel driver in Prevx Pro 2005 1.0 does not verify the source of certain messages, which allows local users to bypass protection by sending certain messages to the driver, as demonstrated by sending an "allow" message to bypass a warning message.
local
low complexity
prevx
4.6
2005-07-05 CVE-2005-2144 Local Security vulnerability in Prevx PRO 2005 1.0
Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.
local
low complexity
prevx
2.1
2005-07-05 CVE-2005-2143 Unspecified vulnerability in Microsoft Frontpage
Microsoft Front Page allows attackers to cause a denial of service (crash) via a crafted style tag in a web page.
network
low complexity
microsoft
5.0
2005-07-05 CVE-2005-2142 Directory Traversal vulnerability in Kmint21 Software Golden FTP Server 2.60
Directory traversal vulnerability in Golden FTP Server 2.60 allows remote authenticated attackers to list arbitrary directories via a "\.." (backslash dot dot) in an LS (LIST) command.
local
low complexity
kmint21-software
2.1
2005-07-05 CVE-2005-2141 Denial-Of-Service vulnerability in Jollybox.De TCP Chat 1.0
TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow.
network
low complexity
jollybox-de
5.0
2005-07-05 CVE-2005-2140 Directory Traversal vulnerability in Fsboard 2.0
Directory traversal vulnerability in default.asp for FSboard 2.0 allows remote attackers to read arbitrary files via ".." sequences in the filename parameter.
network
low complexity
fsboard
5.0
2005-07-05 CVE-2005-2139 Remote Security vulnerability in Pavsta Auto Site
PHP remote file inclusion vulnerability in user_check.php for Pavsta Auto Site allows remote attackers to execute arbitrary PHP code via the sitepath parameter.
network
low complexity
pavsta
5.0
2005-07-05 CVE-2005-2138 Cross-Site Scripting vulnerability in Comdev Ecommerce 3.0/3.1
Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message.
network
comdev
4.3
2005-07-05 CVE-2005-2137 Unspecified vulnerability in Nateon Messenger 3.0
Unknown vulnerability in NateOn Messenger 3.0 allows remote attackers to list arbitrary directories via unknown attack vectors.
network
low complexity
nateon
5.0