Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-06-16 CVE-2005-1721 Unspecified vulnerability in Apple AFP Server
Buffer overflow in the legacy client support for AFP Server for Mac OS X 10.4.1 allows attackers to execute arbitrary code.
network
low complexity
apple
7.5
2005-06-16 CVE-2005-1475 Open Redirect vulnerability in Opera Browser
The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.
network
low complexity
opera CWE-601
7.5
2005-06-15 CVE-2005-2002 SQL Injection vulnerability in Mambo Open Source Com_Contents
SQL injection vulnerability in content.php in Mambo 4.5.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user_rating parameter.
network
low complexity
mambo
7.5
2005-06-15 CVE-2005-2000 SQL-Injection vulnerability in paFileDB
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in the team login form, or (3) to auth.php, (4) select, (5) id, or (6) query parameter to pafiledb.php, or (7) string parameter to search.php.
network
low complexity
php-arena
7.5
2005-06-15 CVE-2005-1306 XXE vulnerability in Adobe Acrobat and Acrobat Reader
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to determine the existence of files via Javascript containing XML script, aka the "XML External Entity vulnerability."
network
low complexity
adobe CWE-611
7.5
2005-06-14 CVE-2005-1216 Unspecified vulnerability in Microsoft ISA Server 2000
Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.
network
low complexity
microsoft
7.5
2005-06-14 CVE-2005-1215 Unspecified vulnerability in Microsoft ISA Server 2000
Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.
network
low complexity
microsoft
7.5
2005-06-14 CVE-2005-1213 Buffer Overflow vulnerability in Microsoft Outlook Express NNTP Response Parsing
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.
network
low complexity
microsoft
7.5
2005-06-14 CVE-2005-1212 Buffer Overflow vulnerability in Microsoft Step-By-Step Interactive Training Bookmark Link
Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.
network
low complexity
microsoft
7.5
2005-06-14 CVE-2005-1207 Unspecified vulnerability in Microsoft Windows 2003 Server and Windows XP
Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.
local
low complexity
microsoft
7.2