Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-12-31 CVE-2005-4860 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Spectrumcu Cash Receipting System
Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PASSFILE password file, which makes it easier for local users to gain privileges by decrypting a password.
local
low complexity
spectrumcu CWE-327
7.8
2005-12-31 CVE-2005-4844 Unspecified vulnerability in Microsoft Internet Explorer
The CLSID_ApprenticeICW control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
network
microsoft
7.1
2005-12-31 CVE-2005-4843 Unspecified vulnerability in Microsoft Internet Explorer 7.0
The SmartConnect Class control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
network
low complexity
microsoft
7.8
2005-12-31 CVE-2005-4842 Unspecified vulnerability in Microsoft Internet Explorer 7.0
The System Monitor Source Properties control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
network
microsoft
7.1
2005-12-31 CVE-2005-4841 Unspecified vulnerability in Microsoft Internet Explorer 7.0
The Outlook Progress Ctl control allows remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control's CLSID, which is not intended for use within Internet Explorer.
network
microsoft
7.1
2005-12-31 CVE-2005-4835 Denial-Of-Service vulnerability in MADWifi
The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strength, and possibly other vectors related to a race condition between interface enabling and packet transmission.
network
madwifi
7.1
2005-12-31 CVE-2005-4832 Remote SQL Injection vulnerability in Oracle 10g Database SUBSCRIPTION_NAME
SQL injection vulnerability in the Oracle Database Server 10g allows remote authenticated users to execute arbitrary SQL commands with elevated privileges via the SUBSCRIPTION_NAME parameter in the (1) SYS.DBMS_CDC_SUBSCRIBE and (2) SYS.DBMS_CDC_ISUBSCRIBE packages, a different vector than CVE-2005-1197.
network
low complexity
oracle
7.5
2005-12-31 CVE-2005-4830 Unspecified vulnerability in Viewcvs 0.9.2
CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the content-type parameter.
network
high complexity
viewcvs
7.6
2005-12-31 CVE-2005-4827 Internet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of the intended domain by calling open on an XMLHttpRequest object (Microsoft.XMLHTTP) and using tab, newline, and carriage return characters within the first argument (method name), which is supported by some proxy servers that convert tabs to spaces.
network
low complexity
microsoft canon
7.5
2005-12-31 CVE-2005-4824 Remote Security vulnerability in Siteframe
PHP remote file inclusion vulnerability in web/classes.php in Siteframe before 3.2.2 allows remote attackers to execute arbitrary PHP code via a URL in the LOCAL_PATH parameter, a different vulnerability than CVE-2005-1965.
network
low complexity
glen-campbell
7.5