Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-06-13 CVE-2005-1474 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.
network
low complexity
apple
7.5
2005-06-13 CVE-2005-1473 Unspecified vulnerability in Apple mac OS X 10.4.1
SecurityAgent in Apple Mac OS X 10.4.1 allows attackers with physical access to bypass the locked screensaver and launch background applications by opening a URL from a text input field.
local
low complexity
apple
4.6
2005-06-13 CVE-2005-0151 Unspecified vulnerability in Adobe Creative Suite, Photoshop and Premiere
Unknown vulnerability in the installation of Adobe License Management Service, as used in Adobe Photoshop CS, Adobe Creative Suite 1.0, and Adobe Premiere Pro 1.5, allows attackers to gain administrator privileges.
network
low complexity
adobe
7.5
2005-06-12 CVE-2005-1959 Remote Arbitrary Command Execution vulnerability in Jammail 1.8
jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the mail parameter.
network
low complexity
jammail
7.5
2005-06-12 CVE-2005-1957 Improper Authentication vulnerability in Adam Mmedici File Upload Manager
mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.
network
low complexity
adam-mmedici CWE-287
7.5
2005-06-12 CVE-2005-1956 File-Upload vulnerability in File Upload Manager
File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks.
network
low complexity
file-upload-manager
5.0
2005-06-12 CVE-2005-1955 Cross-Site Scripting vulnerability in Singapore 0.9.11Beta
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter.
network
singapore
4.3
2005-06-12 CVE-2005-1729 Denial-Of-Service vulnerability in Novell Edirectory 8.7.3
Novell eDirectory 8.7.3 allows remote attackers to cause a denial of service (application crash) via a URL containing an MS-DOS device name such as AUX, CON, PRN, COM1, or LPT1.
network
low complexity
novell
5.0
2005-06-11 CVE-2005-1953 Remote Security vulnerability in Pico Server Pico Server 3.3
Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request.
network
low complexity
pico-server
7.5
2005-06-10 CVE-2005-1966 Remote Command Execution vulnerability in E107 1.0.1
The eTrace_validaddr function in eTrace plugin for e107 portal allows remote attackers to execute arbitrary commands via shell metacharacters after a valid argument to the etrace_host parameter.
network
low complexity
e107
7.5