Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-05-06 CVE-2005-1471 Unspecified vulnerability in RSA Securid web Agent 5/5.2/5.3
Heap-based buffer overflow in RSA SecurID Web Agent 5, 5.2, and 5.3 allows remote attackers to execute arbitrary code via crafted chunked-encoding data.
network
low complexity
rsa
7.5
2005-05-04 CVE-2005-1342 Multiple vulnerability in Apple Mac OS X
The x-man-page: URI handler for Apple Terminal 1.4.4 in Mac OS X 10.3.9 does not cleanse terminal escape sequences, which allows remote attackers to execute arbitrary commands.
network
low complexity
apple
7.5
2005-05-04 CVE-2005-1340 Remote Security vulnerability in Apple mac OS X 10.3.9
The HTTP proxy service in Server Admin for Mac OS X 10.3.9 does not restrict access when it is enabled, which allows remote attackers to use the proxy.
network
low complexity
apple
7.5
2005-05-04 CVE-2005-1339 Remote Security vulnerability in Mac OS X Server
lukemftpd in Mac OS X 10.3.9 allows remote authenticated users to escape the chroot environment by logging in with their full name.
network
low complexity
apple
7.5
2005-05-04 CVE-2005-1337 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Apple Help Viewer 2.0.7 and 3.0.0 in Mac OS X 10.3.9 allows remote attackers to read and execute arbitrary scrpts with less restrictive privileges via a help:// URI.
network
low complexity
apple
7.5
2005-05-04 CVE-2005-1335 Local Security vulnerability in Mac OS X Server
Unknown vulnerability in Mac OS X 10.3.9 allows local users to gain privileges via (1) chfn, (2) chpass, and (3) chsh, which "use external helper programs in an insecure manner."
local
low complexity
apple
7.2
2005-05-04 CVE-2005-1332 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Bluetooth-enabled systems in Mac OS X 10.3.9 enables the Bluetooth file exchange service by default, which allows remote attackers to access files without the user being notified, and local users to access files via the default directory.
network
low complexity
apple
7.5
2005-05-04 CVE-2005-0676 SQL-Injection vulnerability in PHPoutsourcing Zorum 3.5
index.php in Zorum 3.5 allows remote attackers to trigger an SQL error, and possibly inject arbitrary SQL commands, via the search capability.
network
low complexity
phpoutsourcing
7.5
2005-05-04 CVE-2005-0594 Unspecified vulnerability in Apple mac OS X Server 10.3.9
Buffer overflow in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code.
local
low complexity
apple
7.2
2005-05-03 CVE-2005-1826 Remote Security vulnerability in HP Radia Client 3.1.0.0
Buffer overflow in HP Radia Notify Daemon 3.1.0.0 (formerly by Novadigm), and other versions including 2.x, 3.x, and 4.x, allows remote attackers to execute arbitrary code via a long file extension.
network
low complexity
hp
7.5