Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-1068 Cross-site scripting (XSS) vulnerability in sCssBoard 1.11 and earlier allows remote attackers to execute arbitrary Javascript via [url] tags.
network
scssboard
4.3
2005-05-02 CVE-2005-1066 Unspecified vulnerability in University of Washington Pine 4.62
Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack.
local
high complexity
university-of-washington
1.2
2005-05-02 CVE-2005-1065 Unspecified vulnerability in Novell Linux Desktop 9
tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.
local
low complexity
novell
2.1
2005-05-02 CVE-2005-1062 Remote Security vulnerability in Kerio products
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods.
network
low complexity
kerio
7.5
2005-05-02 CVE-2005-1061 The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."
network
low complexity
logwatch redhat
5.0
2005-05-02 CVE-2005-1060 Remote Denial Of Service vulnerability in Novell Netware 6.0/6.5
Unknown vulnerability in the TCP/IP functionality (TCPIP.NLM) in Novell Netware 6.x allows remote attackers to cause a denial of service (ABEND by Page Fault Processor Exception) via certain packets.
network
low complexity
novell
5.0
2005-05-02 CVE-2005-1059 Remote Authentication Bypass vulnerability in Linksys WET11 Password Update
Linksys WET11 1.5.4 allows remote attackers to change the password without providing the original password via the data parameter to changepw.html.
local
low complexity
linksys
2.1
2005-05-02 CVE-2005-1058 Unspecified vulnerability in Cisco IOS 12.2T/12.3/12.3T
Cisco IOS 12.2T, 12.3 and 12.3T, when processing an ISAKMP profile that specifies XAUTH authentication after Phase 1 negotiation, may not process certain attributes in the ISAKMP profile that specifies XAUTH, which allows remote attackers to bypass XAUTH and move to Phase 2 negotiations.
network
low complexity
cisco
7.5
2005-05-02 CVE-2005-1057 Unspecified vulnerability in Cisco IOS 12.2T/12.3/12.3T
Cisco IOS 12.2T, 12.3 and 12.3T, when using Easy VPN Server XAUTH version 6 authentication, allows remote attackers to bypass authentication via a "malformed packet."
network
low complexity
cisco
7.5
2005-05-02 CVE-2005-1056 Remote Denial of Service vulnerability in HP OpenView Network Node Manager
Unknown vulnerability in HP OpenView Network Node Manager (NMM) 6.2 through 6.4, and 7.01 through 7.50, allows remote attackers to cause a denial of service.
network
low complexity
hp
5.0