Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0498 Information Disclosure vulnerability in Gigafast Router
Gigafast router (aka CompUSA router) allows remote attackers to gain sensitive information and bypass the login page via a direct request to backup.cfg, which reveals the administrator password in plaintext.
network
low complexity
gigafast-ethernet
7.5
2005-05-02 CVE-2005-0497 Local Security vulnerability in Elite System Max 9000
ADP Elite System Max 9000 allows remote authenticated users to gain privileges by uploading a .profile that sets the ADPROOT environment variable to the root directory.
local
low complexity
adp
7.2
2005-05-02 CVE-2005-0493 Security Bypass vulnerability in Biz Mail Form
CRLF injection vulnerability in bizmail.cgi in Biz Mail Form before 2.2 allows remote attackers to bypass the email check and send spam e-mail via CRLF sequences and forged mail headers in the email parameter.
network
low complexity
seth-m-knorr
5.0
2005-05-02 CVE-2005-0492 Improper Input Validation vulnerability in Adobe Acrobat Reader 6.0.3/7.0
Adobe Acrobat Reader 6.0.3 and 7.0.0 allows remote attackers to cause a denial of service (application crash) via a PDF file that contains a negative Count value in the root page node.
network
high complexity
adobe CWE-20
2.6
2005-05-02 CVE-2005-0491 Remote Stack-Based Buffer Overrun vulnerability in Knox Arkeia Type 77 Request
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a long type 77 request.
network
low complexity
knox-software
critical
10.0
2005-05-02 CVE-2005-0490 Incorrect Calculation of Buffer Size vulnerability in Haxx Curl and Libcurl
Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c during NTLM authentication or (2) the Curl_krb_kauth and krb4_auth functions in krb4.c during Kerberos authentication.
network
low complexity
haxx CWE-131
8.8
2005-05-02 CVE-2005-0469 Remote Buffer Overflow vulnerability in Multiple Vendor Telnet Client LINEMODE Sub-Options
Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands.
network
low complexity
ncsa
7.5
2005-05-02 CVE-2005-0468 Buffer Overflow vulnerability in Ncsa Telnet C
Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated.
network
low complexity
ncsa
7.5
2005-05-02 CVE-2005-0465 Unspecified vulnerability in SGI Irix
gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.
local
low complexity
sgi
2.1
2005-05-02 CVE-2005-0464 Unspecified vulnerability in SGI Irix 6.5.22
gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.
local
low complexity
sgi
2.1