Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-05-14 CVE-2005-1544 Buffer Overflow vulnerability in LibTIFF TIFFOpen
Stack-based buffer overflow in libTIFF before 3.7.2 allows remote attackers to execute arbitrary code via a TIFF file with a malformed BitsPerSample tag.
network
low complexity
libtiff
7.5
2005-05-12 CVE-2005-1567 SQL-Injection vulnerability in Directtopics
SQL injection vulnerability in topic.php in DirectTopics 2.1 and 2.2 allows remote attackers to execute arbitrary SQL commands via the topic parameter.
network
low complexity
directtopics
7.5
2005-05-12 CVE-2005-1564 Remote Security vulnerability in Bugzilla
post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug entry" by modifying the URL to specify the name of the product.
network
low complexity
mozilla
7.5
2005-05-12 CVE-2005-1532 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.
network
low complexity
mozilla CWE-264
7.5
2005-05-12 CVE-2005-1531 Script Manager Security Bypass vulnerability in Mozilla Suite And Firefox
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."
network
low complexity
mozilla
7.5
2005-05-12 CVE-2005-0974 Unspecified vulnerability in Apple mac OS X
Unknown vulnerability in the nfs_mount call in Mac OS X 10.3.9 and earlier allows local users to gain privileges via crafted arguments.
local
low complexity
apple
7.2
2005-05-12 CVE-2005-0972 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Integer overflow in the searchfs system call in Mac OS X 10.3.9 and earlier allows local users to execute arbitrary code via crafted parameters.
local
low complexity
apple
7.2
2005-05-11 CVE-2005-1585 SQL-Injection vulnerability in Open Solution Quick.Forum 2.1.6
Multiple SQL injection vulnerabilities in Quick.Forum 2.1.6 allow remote attackers to execute arbitrary SQL commands via the (1) iCategory or (2) page parameter to index.php, or (3) iCategory parameter in the query string to the forum directory.
network
low complexity
open-solution
7.5
2005-05-11 CVE-2005-1580 Remote Arbitrary File Upload vulnerability in Boastmachine 3.0
users.ini.php in BoastMachine 3.0 does not properly restrict the types of files that can be uploaded, which allows remote attackers to execute arbitrary code.
network
low complexity
boastmachine
7.5
2005-05-11 CVE-2005-1562 Remote vulnerability in MaxWebPortal
Multiple SQL injection vulnerabilities in MaxWebPortal 1.3.5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fpassword parameter to inc_functions.asp, (2) txtAddress, (3) message, or (4) subject parameter to post_info.asp, (5) andor parameter to search.asp, (6) verkey parameter to pop_profile.asp, or (7) Remove or (8) Delete parameter to pm_delete2.asp.
network
low complexity
maxwebportal
7.5