Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-11-18 CVE-2005-3679 Unspecified vulnerability in Activecampaign 1-2-All Broadcast Email 4.07
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username field in the admin control panel.
network
low complexity
activecampaign
7.5
2005-11-18 CVE-2005-3677 Unspecified vulnerability in Realnetworks Realplayer
Buffer overflow in RealNetworks RealPlayer 10 and 10.5 allows remote attackers to execute arbitrary code via a crafted image in a RealPlayer Skin (RJS) file.
network
low complexity
realnetworks
7.5
2005-11-18 CVE-2005-3676 Unspecified vulnerability in PHPwebthings 1.4.4
SQL injection vulnerability in download.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL commands via the file parameter.
network
low complexity
phpwebthings
7.5
2005-11-18 CVE-2005-3675 Unspecified vulnerability in TCP
The Transmission Control Protocol (TCP) allows remote attackers to cause a denial of service (bandwidth consumption) by sending ACK messages for packets that have not yet been received (optimistic ACKs), which can cause the sender to increase its transmission rate until it fills available bandwidth.
network
low complexity
tcp
7.8
2005-11-18 CVE-2005-3314 Buffer Errors vulnerability in Novell Netmail 3.5.2
Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code via "long verb arguments."
network
low complexity
novell CWE-119
7.5
2005-11-18 CVE-2005-3674 Denial Of Service vulnerability in SUN Solaris 10.0/9.0
The Internet Key Exchange version 1 (IKEv1) implementation in the libike library in Sun Solaris 9 and 10 allows remote attackers to cause a denial of service (in.iked crash) via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
sun
7.8
2005-11-18 CVE-2005-3673 Denial of Service vulnerability in Check Point Firewall-1 and VPN-1 ISAKMP IKE
The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
checkpoint
7.8
2005-11-18 CVE-2005-3671 Denial Of Service vulnerability in Openswan IKE Traffic
The Internet Key Exchange version 1 (IKEv1) implementation in Openswan 2 (openswan-2) before 2.4.4, and freeswan in SUSE LINUX 9.1 before 2.04_1.5.4-1.23, allow remote attackers to cause a denial of service via (1) a crafted packet using 3DES with an invalid key length, or (2) unspecified inputs when Aggressive Mode is enabled and the PSK is known, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
frees-wan openswan xelerance
7.8
2005-11-18 CVE-2005-3670 Denial Of Service vulnerability in HP Hp-Ux, Jetdirect 635N and Tru64
Multiple unspecified vulnerabilities in the Internet Key Exchange version 1 (IKEv1) implementation in HP HP-UX B.11.00, B.11.11, and B.11.23 running IPSec, HP Jetdirect 635n IPv6/IPsec Print Server, and HP Tru64 UNIX 5.1B-3 and 5.1B-2/PK4, allow remote attackers to cause a denial of service via certain IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
hp
7.8
2005-11-18 CVE-2005-3664 Remote Buffer Overflow vulnerability in Kaspersky Anti-Virus Engine CHM File Parser
Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, Anti-Virus On-Demand Scanner for Linux 5.0.5, and F-Secure Anti-Virus for Linux 4.50 allows remote attackers to execute arbitrary code via a crafted CHM file.
network
low complexity
f-secure kaspersky-lab
7.5