Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2005-07-07 CVE-2005-1841 Unspecified vulnerability in Adobe Acrobat Reader 5.0.10/5.0.9
The control for Adobe Reader 5.0.9 and 5.0.10 on Linux, Solaris, HP-UX, and AIX creates temporary files with the permissions as specified in a user's umask, which could allow local users to read PDF documents of that user if the umask allows it.
local
low complexity
adobe
2.1
2005-07-05 CVE-2005-2144 Local Security vulnerability in Prevx PRO 2005 1.0
Prevx Pro 2005 1.0 allows local users to bypass file protection and modify files by using MapViewOfFile to perform memory mapping on the file.
local
low complexity
prevx
2.1
2005-07-05 CVE-2005-2142 Directory Traversal vulnerability in Kmint21 Software Golden FTP Server 2.60
Directory traversal vulnerability in Golden FTP Server 2.60 allows remote authenticated attackers to list arbitrary directories via a "\.." (backslash dot dot) in an LS (LIST) command.
local
low complexity
kmint21-software
2.1
2005-07-05 CVE-2005-2134 Denial-Of-Service vulnerability in NetBSD
The (1) clcs and (2) emuxki drivers in NetBSD 1.6 through 2.0.2 allow local users to cause a denial of service (kernel crash) by using the set-parameters ioctl on an audio device to change the block size and set the pause state to "unpaused" in the same ioctl, which causes a divide-by-zero error.
local
low complexity
netbsd
2.1
2005-07-05 CVE-2005-1932 Input Validation vulnerability in LPanel
Lpanel 1.59 and earlier, and other versions before 1.597, allows remote authenticated users to modify certain critical variables and (1) modify DNS settings for arbitrary domains via the domain parameter to diagnose.php, (2) close, open, or respond to arbitrary support tickets via the close, open, or pid parameter to view_ticket.php, (3) obtain sensitive information on arbitrary invoices via the inv parameter to viewreceipt.php, or (4) modify domain information for arbitrary domains via the editdomain parameter to domains.php.
local
low complexity
lpanel
2.1
2005-07-05 CVE-2005-1923 Unspecified vulnerability in Clam Anti-Virus Clamav
The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to 0xff, which causes a zero-length read.
network
high complexity
clam-anti-virus
2.6
2005-07-05 CVE-2005-1917 Unspecified vulnerability in Kpopper 1.0
kpopper 1.0 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the .popper-new temporary file.
local
low complexity
kpopper
2.1
2005-06-29 CVE-2005-2078 Remote Denial Of Service vulnerability in Sofotex Bisonftp V4R1
BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument.
local
low complexity
sofotex
2.1
2005-06-29 CVE-2005-2076 Unspecified vulnerability in HP Version Control Repository Manager
HP Version Control Repository Manager (VCRM) before 2.1.1.730 does not properly handle the "@" character in a proxy password, which could allow attackers with physical access to obtain portions of the password when it is displayed to the screen.
local
low complexity
hp
2.1
2005-06-29 CVE-2005-2073 Local Security vulnerability in DB2 Universal Database
Unknown vulnerability in IBM DB2 8.1.4 through 8.1.9 and 8.2.0 through 8.2.2 allows local users with SELECT privileges to conduct unauthorized activities and insert, update or delete table contents.
local
low complexity
ibm
2.1