Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0070 Local File Disclosure vulnerability in Synaesthesia
Synaesthesia 2.1 and earlier, and possibly other versions, when installed setuid root, does not drop privileges before processing configuration and mixer files, which allows local users to read arbitrary files.
local
low complexity
synaesthesia
7.2
2005-05-02 CVE-2005-0064 Unspecified vulnerability in Xpdf
Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.
network
low complexity
xpdf
7.5
2005-05-02 CVE-2005-0063 Remote Code Execution vulnerability in Microsoft Windows Shell
The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.
network
low complexity
microsoft
7.5
2005-05-02 CVE-2005-0061 Unspecified vulnerability in Microsoft products
The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.
local
low complexity
microsoft
7.2
2005-05-02 CVE-2005-0060 Unspecified vulnerability in Microsoft products
Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.
local
low complexity
microsoft
7.2
2005-05-02 CVE-2005-0057 Buffer Overflow vulnerability in Microsoft Windows Hyperlink Object Library
The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.
network
low complexity
microsoft
7.5
2005-05-02 CVE-2005-0055 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."
network
low complexity
microsoft
7.5
2005-05-02 CVE-2005-0053 Unspecified vulnerability in Microsoft products
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."
network
low complexity
microsoft
7.5
2005-05-02 CVE-2005-0051 Remote Information Disclosure vulnerability in Microsoft Windows Named Pipe
The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."
network
low complexity
microsoft
7.5
2005-05-02 CVE-2005-0048 Unspecified vulnerability in Microsoft Windows 2000 and Windows XP
Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."
network
low complexity
microsoft
7.5