Vulnerabilities > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-05-17 | CVE-2005-1637 | Unspecified vulnerability in Npds 4.8/5.0 Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments.php. | 7.5 |
2005-05-17 | CVE-2005-1633 | Unspecified vulnerability in Jgs-Xa Jgs-Portal Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php. | 7.5 |
2005-05-17 | CVE-2005-1632 | Unspecified vulnerability in Tavis Rudd Cheetah 0.9.15/0.9.16 Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, which allows local users to execute arbitrary code via a malicious module in /tmp/. | 7.2 |
2005-05-17 | CVE-2005-1630 | Remote Security vulnerability in Attachment Mod Unknown vulnerability in Attachment Mod before 2.3.13, related to a "serious issue with realnames," has unknown impact and attack vectors. | 7.5 |
2005-05-17 | CVE-2005-1629 | SQL Injection vulnerability in All Enthusiast PhotoPost PHP Pro Member.PHP SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter. | 7.5 |
2005-05-17 | CVE-2005-1626 | Remote Buffer Overflow vulnerability in Pserv completedPath Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code. | 7.5 |
2005-05-17 | CVE-2005-1589 | Local Memory Corruption vulnerability in Multiple Linux Kernel IOCTL Handlers The pkt_ioctl function in the pktcdvd block device ioctl handler (pktcdvd.c) in Linux kernel 2.6.12-rc4 and earlier calls the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space and allows local users to cause a denial of service and possibly execute arbitrary code, a similar vulnerability to CVE-2005-1264. | 7.2 |
2005-05-17 | CVE-2005-1307 | Local Privilege Escalation vulnerability in Adobe Version Cue The (1) stopserver.sh and (2) startserver.sh scripts in Adobe Version Cue on Mac OS X uses the current working directory to find and execute the productname.sh script, which allows local users to execute arbitrary code by copying and calling the scripts from a user-controlled directory. | 7.2 |
2005-05-17 | CVE-2005-1264 | Local Memory Corruption vulnerability in Multiple Linux Kernel IOCTL Handlers Raw character devices (raw.c) in the Linux kernel 2.6.x call the wrong function before passing an ioctl to the block device, which crosses security boundaries by making kernel address space accessible from user space, a similar vulnerability to CVE-2005-1589. | 7.2 |
2005-05-16 | CVE-2005-1616 | Information Disclosure vulnerability in Ultimate PHP Board viewforum.php in Ultimate PHP Board (UPB) 1.8 through 1.9.6 allows remote attackers to obtain sensitive information via an invalid (1) id or possibly (2) postorder parameter, which reveals the path in an error message when a file can not be opened. | 7.5 |