Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-04 CVE-2005-1332 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
network
low complexity
apple
7.5
2005-05-04 CVE-2005-1331 Multiple vulnerability in Apple Mac OS X
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control characters, and homographs.
network
high complexity
apple
5.1
2005-05-04 CVE-2005-1330 Improper Input Validation vulnerability in Apple mac OS X and mac OS X Server
AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.
local
low complexity
apple CWE-20
4.9
2005-05-04 CVE-2005-1194 Remote Buffer Overflow vulnerability in Redhat products
Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.
local
low complexity
redhat
4.6
2005-05-04 CVE-2005-0676 SQL-Injection vulnerability in PHPoutsourcing Zorum 3.5
index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.
network
low complexity
phpoutsourcing
7.5
2005-05-04 CVE-2005-0594 Unspecified vulnerability in Apple mac OS X Server 10.3.9
Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.
local
low complexity
apple
7.2
2005-05-03 CVE-2005-1826 Remote Security vulnerability in HP Radia Client 3.1.0.0
Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension.
network
low complexity
hp
7.5
2005-05-03 CVE-2005-1825 Unspecified vulnerability in HP Radia Client 3.1.2.0
Multiple stack-based buffer overflows in the nvd_exec function in HP Radia Notify Daemon 3.1.2.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a command with crafted parameters to a RADEXECD process.
network
low complexity
hp
7.5
2005-05-03 CVE-2005-1452 Remote Security vulnerability in Serendipity
Serendipity before 0.8 allows Chief users to "hide plugins installed by other users."
network
low complexity
s9y
critical
10.0
2005-05-03 CVE-2005-1451 Remote Security vulnerability in Serendipity
The media manager in Serendipity before 0.8 allows remote attackers to upload and execute arbitrary (1) .php or (2) .shtml files.
network
low complexity
s9y
7.5