Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-12 CVE-2005-1531 Script Manager Security Bypass vulnerability in Mozilla Suite And Firefox
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."
network
low complexity
mozilla
7.5
2005-05-12 CVE-2005-0974 Unspecified vulnerability in Apple mac OS X
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
local
low complexity
apple
7.2
2005-05-12 CVE-2005-0973 Unspecified vulnerability in Apple mac OS X
Unknown vulnerability in the setsockopt system call in Mac OS X 10.3.9 and earlier allows local users to cause a denial of service (memory exhaustion) via crafted arguments.
local
low complexity
apple
2.1
2005-05-12 CVE-2005-0972 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
local
low complexity
apple
7.2
2005-05-12 CVE-2005-0971 Unspecified vulnerability in Apple mac OS X
Stack-based buffer overflow in the semop system call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
local
low complexity
apple
4.6
2005-05-12 CVE-2005-0969 Unspecified vulnerability in Apple mac OS X
Heap-based buffer overflow in the syscall emulation functionality in Mac OS X before 10.3.9 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via crafted parameters.
local
low complexity
apple
4.6
2005-05-11 CVE-2005-1585 SQL-Injection vulnerability in Open Solution Quick.Forum 2.1.6
Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.
network
low complexity
open-solution
7.5
2005-05-11 CVE-2005-1580 Remote Arbitrary File Upload vulnerability in Boastmachine 3.0
users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.
network
low complexity
boastmachine
7.5
2005-05-11 CVE-2005-1572 Denial-Of-Service vulnerability in Wenig and Spitzer-Williams Showoff Digital Media Software 1.5.4
ShowOff! 1.5.4 allows remote attackers to cause a denial of service (server crash) via a malformed request to port 8083.
network
low complexity
wenig-and-spitzer-williams
5.0
2005-05-11 CVE-2005-1562 Remote vulnerability in MaxWebPortal
Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to search.asp, (6) verkey parameter to pop_profile.asp, or (7) Remove or (8) Delete parameter to pm_delete2.asp.
network
low complexity
maxwebportal
7.5