Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2005-03-01 CVE-2004-1002 Integer Underflow (Wrap or Wraparound) vulnerability in multiple products
Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.
network
low complexity
samba canonical CWE-191
7.5
2005-03-01 CVE-2004-0986 Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
network
low complexity
suse debian linux redhat
7.5
2005-02-28 CVE-2005-0608 Denial-Of-Service vulnerability in Webmod 0.47
Heap-based buffer overflow in server.cpp for WebMod 0.47 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a POST request with a Content-Length that is less than the amount of data that is actually sent.
network
low complexity
webmod
7.5
2005-02-25 CVE-2005-0107 Unspecified vulnerability in Debian Bsmtpd 2.3
bsmtpd 2.3 and earlier does not properly sanitize e-mail addresses, which allows remote attackers to execute arbitrary commands.
network
low complexity
debian
7.5
2005-02-23 CVE-2005-0516 Remote Security vulnerability in Imagegalleryplugin
The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.
network
low complexity
twiki
7.5
2005-02-22 CVE-2005-0535 Cross-site request forgery (CSRF) vulnerability in MediaWiki 1.3.x before 1.3.11 and 1.4 beta before 1.4 rc1 allows remote attackers to perform unauthorized actions as authenticated MediaWiki users.
network
low complexity
mediawiki gentoo
7.5
2005-02-21 CVE-2005-0537 SQL-Injection vulnerability in Igeneric Free Shopping Cart 1.2
Multiple SQL injection vulnerabilities in page.php for iGeneric (iG) Shop 1.2 may allow remote attackers to execute arbitrary SQL statements via the (1) cats, (2) l_price, or (3) u_price parameters.
network
low complexity
igeneric
7.5
2005-02-21 CVE-2005-0512 Remote Security vulnerability in Mambo
PHP remote file inclusion vulnerability in Tar.php in Mambo 4.5.2 allows remote attackers to execute arbitrary PHP code by modifying the mosConfig_absolute_path parameter to reference a URL on a remote web server that contains the code, a different vulnerability than CVE-2004-1693.
network
low complexity
mambo
7.5
2005-02-21 CVE-2005-0511 Unspecified vulnerability in Jelsoft Vbulletin
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers to execute arbitrary PHP code via nested variables in the template parameter.
network
low complexity
jelsoft
7.5
2005-02-21 CVE-2005-0494 Denial-Of-Service vulnerability in Thomson Cable Modem Tcw690
The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly validate the password before performing changes, which allows remote attackers on the LAN to gain access via a direct POST request.
network
low complexity
thomson
7.5