Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-14 CVE-2005-1544 Buffer Overflow vulnerability in LibTIFF TIFFOpen
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.
network
low complexity
libtiff
7.5
2005-05-13 CVE-2005-1578 Local Security vulnerability in Guidance Software Encase 4.18A
EnCase Forensic Edition 4.18a does not support Device Configuration Overlays (DCO), which allows attackers to hide information without detection.
local
low complexity
guidance-software
2.1
2005-05-13 CVE-2005-0758 zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.
local
low complexity
gnu canonical
4.6
2005-05-12 CVE-2005-1579 Information Disclosure vulnerability in Apple Quicktime 7.0
Apple QuickTime Player 7.0 on Mac OS X 10.4 allows remote attackers to obtain sensitive information via a .mov file with a Quartz Composer composition (.qtz) file that uses certain patches to read local information, then other patches to send the information to the attacker.
network
low complexity
apple
5.0
2005-05-12 CVE-2005-1576 Remote Security vulnerability in Mozilla Firefox 0.10.1/1.0
The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.
network
high complexity
mozilla
2.6
2005-05-12 CVE-2005-1568 Information Disclosure vulnerability in Directtopics
topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to obtain sensitive information via an invalid topic parameter, which reveals the path in an error message.
network
low complexity
directtopics
5.0
2005-05-12 CVE-2005-1567 SQL-Injection vulnerability in Directtopics
SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.
network
low complexity
directtopics
7.5
2005-05-12 CVE-2005-1565 Information Disclosure vulnerability in Bugzilla Authentication
Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the URL, which may allow local users to gain sensitive information from web logs or browser history.
network
low complexity
mozilla
5.0
2005-05-12 CVE-2005-1564 Remote Security vulnerability in Bugzilla
post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.
network
low complexity
mozilla
7.5
2005-05-12 CVE-2005-1532 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
network
low complexity
mozilla CWE-264
7.5