Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-10-27 CVE-2005-3334 Cross-Site Scripting vulnerability in Flyspray 0.9.7/0.9.8
Cross-site scripting (XSS) vulnerability in index.php in Flyspray 0.9.7 through 0.9.8 (devel) allows remote attackers to inject arbitrary web script or HTML via the (1) PHPSESSID, (2) task, (3) string, (4) type, (5) serv, (6) due, (7) dev, and (8) sort2 parameters.
network
flyspray
4.3
2005-10-27 CVE-2005-3329 Cross-Site Scripting vulnerability in RSA ACE Agent Image
Cross-site scripting (XSS) vulnerability in RSA Authentication Agent for Web 5.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the image parameter in a GetPic operation.
network
rsa
4.3
2005-10-27 CVE-2005-3322 Denial of Service vulnerability in SUSE Linux Squid Proxy SSL Handling
Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).
network
low complexity
squid suse
5.0
2005-10-27 CVE-2005-3321 chkstat in SuSE Linux 9.0 through 10.0 allows local users to modify permissions of files by creating a hardlink to a file from a world-writable directory, which can cause the link count to drop to 1 when the file is deleted or replaced, which is then modified by chkstat to use weaker permissions.
local
low complexity
novell suse
4.6
2005-10-27 CVE-2005-3318 Stack Buffer Overflow vulnerability in Jed Wing CHM Lib
Buffer overflow in the _chm_decompress_block function in CHM lib (chmlib) before 0.37, as used in products such as KchmViewer, allows attackers to execute arbitrary code, a different vulnerability than CVE-2005-2930.
network
high complexity
jed-wing
5.1
2005-10-27 CVE-2005-2338 HTML Injection vulnerability in XOOPS
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.12 JP and earlier, XOOPS 2.0.13.1 and earlier, and 2.2.x up to 2.2.3 RC1 allow remote attackers to inject arbitrary web script or HTML via (1) modules that use "XOOPS Code" and (2) newbb in the forum module.
network
xoops
4.3
2005-10-26 CVE-2005-3312 Unspecified vulnerability in Microsoft Internet Explorer 6.0
The HTML rendering engine in Microsoft Internet Explorer 6.0 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML in corrupted images and other files such as .GIF, JPG, and WAV, which is rendered as HTML when the user clicks on the link, even though the web server response and file extension indicate that it should be treated as a different file type.
network
microsoft
4.3
2005-10-26 CVE-2005-3308 HTML Injection vulnerability in Zomplog 3.3/3.4
Multiple cross-site scripting (XSS) vulnerabilities in Zomplog 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) comment parameter in detail.php, (3) the username parameter in get.php, and (4) the search parameter in index.php.
network
zomplog
4.3
2005-10-26 CVE-2005-3307 Remote File Include vulnerability in FlatNuke
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operation or (2) quale parameter in a newtopic operation.
network
low complexity
flatnuke
5.0
2005-10-26 CVE-2005-3306 Unspecified vulnerability in Flatnuke 2.5.6
Cross-site scripting (XSS) vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the user parameter in a profile operation, a different vulnerability than CVE-2005-2814.
network
flatnuke
4.3