Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-11-23 CVE-2005-3779 Local Unauthorized Access vulnerability in HP Hp-Ux 11.00/11.11/11.23
Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.
local
low complexity
hp
7.2
2005-11-23 CVE-2005-3775 Code Injection vulnerability in Pollvote
PHP remote file inclusion vulnerability in pollvote.php in PollVote allows remote attackers to include arbitrary files via a URL in the pollname parameter.
network
low complexity
pollvote CWE-94
7.5
2005-11-23 CVE-2005-3772 Input Validation vulnerability in Joomla
Multiple SQL injection vulnerabilities in Joomla! before 1.0.4 allow remote attackers to execute arbitrary SQL commands via the (1) Itemid variable in the Polls modules and (2) multiple unspecified methods in the mosDBTable class.
network
low complexity
joomla
7.5
2005-11-23 CVE-2005-3769 SQL Injection vulnerability in PHP Download Manager PHP Download Manager 1.1/1.1.2/1.1.3
SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.
network
low complexity
php-download-manager
7.5
2005-11-23 CVE-2005-3768 Denial-Of-Service vulnerability in Gateway Security 400
Buffer overflow in the Internet Key Exchange version 1 (IKEv1) implementation in Symantec Dynamic VPN Services, as used in Enterprise Firewall, Gateway Security, and Firewall /VPN Appliance products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
symantec
7.5
2005-11-22 CVE-2005-3765 Improper File Permission vulnerability in Exponent Content Management System
Exponent CMS 0.96.3 and later versions performs a chmod on uploaded files to give them execute permissions, which allows remote attackers to execute arbitrary code.
network
low complexity
exponent
7.5
2005-11-22 CVE-2005-3762 SQL Injection vulnerability in Exponent CMS
SQL injection vulnerability in the navigation module (navigationmodule) in Exponent CMS 0.96.3 and later versions allows remote attackers to execute arbitrary SQL commands via the parent parameter.
network
low complexity
exponent
7.5
2005-11-22 CVE-2005-3760 Buffer Errors vulnerability in IBM Websphere Application Server 5.0
Double free vulnerability in the BBOORB module in IBM WebSphere Application Server for z/OS 5.0 allows attackers to cause a denial of service (ABEND).
network
low complexity
ibm CWE-119
7.8
2005-11-22 CVE-2005-3757 Remote vulnerability in Google Mini Search Appliance and Search Appliance
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to obtain sensitive information and execute arbitrary code via dangerous Java class methods in select attribute of xsl:value-of tags in XSLT style sheets, such as (1) system-property, (2) sys:getProperty, and (3) run:exec.
network
low complexity
google
7.5
2005-11-22 CVE-2005-3753 Denial-Of-Service vulnerability in kernel
Linux kernel before after 2.6.12 and before 2.6.13.1 might allow attackers to cause a denial of service (Oops) via certain IPSec packets that cause alignment problems in standard multi-block cipher processors.
network
low complexity
linux
7.8