Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-24 CVE-2005-1740 Unspecified vulnerability in Net-Snmp
fixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute arbitrary commands, or overwrite arbitrary files via a symlink attack.
network
low complexity
net-snmp
critical
10.0
2005-05-24 CVE-2005-1739 Denial Of Service vulnerability in ImageMagick And GraphicsMagick XWD Decoder
The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.
network
low complexity
graphicsmagick imagemagick
5.0
2005-05-24 CVE-2005-1738 Local Format String vulnerability in Iron Bars Shell Iron Bars Shell 0.3A/0.3B/0.3C
Format string vulnerability in the logPrintBadfile function in delbadfiles.c Iron Bars SHell (ibsh) before 0.3d allows users to "access files outside the home directory" and possibly execute arbitrary code via certain inputs that are not properly handled in a syslog call.
network
low complexity
iron-bars-shell
critical
10.0
2005-05-24 CVE-2005-1737 Denial-Of-Service vulnerability in Electricmonk Proms 0.11
Multiple unknown vulnerabilities in PROMS 0.11 allow "non-authorized users" to (1) view or modify the project member list or (2) modify the todos list.
network
low complexity
electricmonk
7.5
2005-05-24 CVE-2005-1736 Remote Security vulnerability in Proms
PROMS 0.11 does not properly handle "certain combinations of rights," which gives more rights to users than intended.
network
low complexity
electricmonk
7.5
2005-05-24 CVE-2005-1735 Unspecified vulnerability in Electricmonk Proms
Multiple cross-site scripting (XSS) vulnerabilities in PROMS before 0.11 allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
electricmonk
4.3
2005-05-24 CVE-2005-1734 Unspecified vulnerability in Electricmonk Proms
Multiple SQL injection vulnerabilities in PROMS before 0.11 allow remote attackers to execute arbitrary SQL commands via unknown vectors.
network
low complexity
electricmonk
7.5
2005-05-24 CVE-2005-1733 Remote Security vulnerability in Cookie Cart
Cookie Cart stores the password file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and encrypted passwords via a direct request to passwd.txt.
network
low complexity
metro-marketing
5.0
2005-05-24 CVE-2005-1732 Remote Security vulnerability in Cookie Cart
Cookie Cart allows remote attackers to read the Order Notification list via the testmycgi and path parameters to testmy.cgi.
network
low complexity
metro-marketing
5.0
2005-05-24 CVE-2005-1719 Unspecified vulnerability in Alwil Avast Antivirus
Unknown vulnerability in ALWIL avast! antivirus 4 (4.6.6230) and earlier, when running on Windows NT 4.0, does not properly detect certain viruses.
network
low complexity
alwil
7.5