Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0199 Integer Underflow (Wrap or Wraparound) vulnerability in Barton Ngircd
Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.
network
low complexity
barton CWE-191
critical
9.8
2005-05-02 CVE-2005-0198 Remote Authentication Bypass vulnerability in University Of Washington IMAP Server CRAM-MD5
A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.
network
low complexity
university-of-washington
7.5
2005-05-02 CVE-2005-0197 Configuration vulnerability in Cisco IOS
Cisco IOS 12.1T, 12.2, 12.2T, 12.3 and 12.3T, with Multi Protocol Label Switching (MPLS) installed but disabled, allows remote attackers to cause a denial of service (device reload) via a crafted packet sent to the disabled interface.
low complexity
cisco CWE-16
6.1
2005-05-02 CVE-2005-0196 Unspecified vulnerability in Cisco IOS
Cisco IOS 12.0 through 12.3YL, with BGP enabled and running the bgp log-neighbor-changes command, allows remote attackers to cause a denial of service (device reload) via a malformed BGP packet.
network
low complexity
cisco
5.0
2005-05-02 CVE-2005-0195 Unspecified vulnerability in Cisco IOS
Cisco IOS 12.0S through 12.3YH allows remote attackers to cause a denial of service (device restart) via a crafted IPv6 packet.
network
low complexity
cisco
5.0
2005-05-02 CVE-2005-0194 Security Bypass vulnerability in Squid
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
network
low complexity
squid
critical
10.0
2005-05-02 CVE-2005-0187 Remote Code Execution vulnerability in AtHoc ToolBar
Stack-based buffer overflow in the SetSkin function in AtHoc toolbar allows remote attackers to execute arbitrary code via a long skin name.
network
low complexity
athoc
7.5
2005-05-02 CVE-2005-0185 Buffer Overflow vulnerability in Mnet Soft Factory Nodemanager Professional 2.00
Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.
network
low complexity
mnet-soft-factory
7.5
2005-05-02 CVE-2005-0184 Directory traversal vulnerability in ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to read arbitrary files via a ..
local
low complexity
squirrelmail
2.1
2005-05-02 CVE-2005-0183 Unspecified vulnerability in Squirrelmail Vacation Plugin
ftpfile in the Vacation plugin 0.15 and earlier for Squirrelmail allows local users to execute arbitrary commands via shell metacharacters in a command line argument.
local
low complexity
squirrelmail
7.2