Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-11-16 CVE-2005-3583 Remote Denial of Service vulnerability in Sun Java Development Kit Font Serialization
(1) Java Runtime Environment (JRE) and (2) Software Development Kit (SDK) 1.4.2_08, 1.4.2_09, and 1.5.0_05 and possibly other versions allow remote attackers to cause a denial of service (JVM unresponsive) via a crafted serialized object, such as a font object as demonstrated on JBoss.
network
low complexity
sun
7.8
2005-11-16 CVE-2005-3582 Packages Insecure RUNPATH vulnerability in Gentoo Linux
ImageMagick before 6.2.4.2-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
local
low complexity
imagemagick
7.2
2005-11-16 CVE-2005-3581 Packages Insecure RUNPATH vulnerability in Gentoo Linux
GDAL before 1.3.0-r1 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
local
low complexity
gdal
7.2
2005-11-16 CVE-2005-3580 Packages Insecure RUNPATH vulnerability in Gentoo Linux
QDBM before 1.8.33-r2 allows local users in the portage group to increase privileges via a shared object in the Portage temporary build directory, which is added to the search path allowing objects in it to be loaded at runtime.
local
low complexity
qdbm
7.2
2005-11-16 CVE-2005-3578 Input Validation vulnerability in Walla TeleSite
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.
network
low complexity
walla-telesite
7.5
2005-11-16 CVE-2005-3575 SQL Injection vulnerability in Cyphor Show.PHP
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
network
low complexity
cynox
7.5
2005-11-16 CVE-2005-3572 SQL Injection vulnerability in Peel 2.6/2.7
SQL injection vulnerability in index.php in Peel 2.6 through 2.7 allows remote attackers to execute arbitrary SQL commands via the rubid parameter.
network
low complexity
peel
7.5
2005-11-16 CVE-2005-3565 Unauthorized Access vulnerability in HP Hp-Ux 11.00/11.11/11.23
Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.
network
low complexity
hp
7.5
2005-11-16 CVE-2005-3564 Local Privilege Escalation vulnerability in HP-UX ENVD
envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.
local
low complexity
hp
7.2
2005-11-16 CVE-2005-3560 Unspecified vulnerability in Zonelabs products
Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in "HTML Modal Dialogs" (window.location.href) contained within JavaScript tags.
network
low complexity
zonelabs
7.5