Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2005-07-12 CVE-2005-2238 Denial-Of-Service vulnerability in IBM AIX 5.1/5.2/5.3
ftpd in IBM AIX 5.1, 5.2 and 5.3 allows remote authenticated users to cause a denial of service (port exhaustion and memory consumption) by using all ephemeral ports.
local
low complexity
ibm
2.1
2005-07-12 CVE-2005-2231 Unspecified vulnerability in High Availability Linux Project Heartbeat 1.2.3
High Availability Linux Project Heartbeat 1.2.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
local
low complexity
high-availability-linux-project
2.1
2005-07-12 CVE-2005-2230 Unspecified vulnerability in Elmo
Electronic Mail Operator (elmo) 1.3.2-r1 and earlier creates the elmostats temporary file insecurely, which allows local users to overwrite arbitrary files.
local
low complexity
elmo
2.1
2005-07-11 CVE-2005-2186 Cross-Site Scripting vulnerability in IntruShield Security Management System
Multiple cross-site scripting (XSS) vulnerabilities in McAfee IntruShield Security Management System allow remote authenticated users to inject arbitrary web script or HTML via the (1) thirdMenuName or (2) resourceName parameter to SystemEvent.jsp.
local
mcafee
1.9
2005-07-11 CVE-2005-2180 Local Security vulnerability in Gnats 4.0/4.1.0
gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.
local
low complexity
gnu
2.1
2005-07-11 CVE-2005-1768 Local Buffer Overflow vulnerability in Linux Kernel IA32 ExecVE
Race condition in the ia32 compatibility code for the execve system call in Linux kernel 2.4 before 2.4.31 and 2.6 before 2.6.6 allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a concurrent thread that increments a pointer count after the nargs function has counted the pointers, but before the count is copied from user space to kernel space, which leads to a buffer overflow.
local
high complexity
linux
3.7
2005-07-08 CVE-2005-2174 Unspecified vulnerability in Mozilla Bugzilla
Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.
network
high complexity
mozilla
2.6
2005-07-07 CVE-2005-1841 Unspecified vulnerability in Adobe Acrobat Reader 5.0.10/5.0.9
The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.
local
low complexity
adobe
2.1
2005-07-05 CVE-2005-2144 Local Security vulnerability in Prevx PRO 2005 1.0
Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.
local
low complexity
prevx
2.1
2005-07-05 CVE-2005-2142 Directory Traversal vulnerability in Kmint21 Software Golden FTP Server 2.60
Directory traversal vulnerability in Golden FTP Server 2.60 allows remote authenticated attackers to list arbitrary directories via a "\.." (backslash dot dot) in an LS (LIST) command.
local
low complexity
kmint21-software
2.1