Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-07-11 CVE-2005-2179 Remote Security vulnerability in JAWS
PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.
network
low complexity
jaws
5.0
2005-07-11 CVE-2005-2177 Improper Input Validation vulnerability in Net-Snmp
Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.
network
low complexity
net-snmp CWE-20
5.0
2005-07-11 CVE-2005-2170 Remote Denial Of Service vulnerability in IBM Tivoli Management Framework 4.1.1
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.
network
low complexity
ibm
5.0
2005-07-11 CVE-2005-2150 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.
network
low complexity
microsoft
5.0
2005-07-11 CVE-2005-1848 Unspecified vulnerability in Phystech Dhcpcd 1.3.17Pl2
The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.
network
low complexity
phystech
5.0
2005-07-09 CVE-2005-2176 Unspecified vulnerability in Novell Netmail
Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
network
low complexity
novell
6.4
2005-07-09 CVE-2005-2175 Remote Security vulnerability in Lotus Notes
The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
network
low complexity
ibm
5.0
2005-07-08 CVE-2005-2173 Unspecified vulnerability in Mozilla Bugzilla
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.
network
low complexity
mozilla
5.0
2005-07-06 CVE-2005-2169 Directory Traversal vulnerability in KAF Oseo Quick and Dirty PHPsource Printer 1.1
Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences.
network
low complexity
kaf-oseo
5.0
2005-07-06 CVE-2005-2163 Cross-Site Scripting vulnerability in Autoindex PHP Script 1.5.2
Cross-site scripting (XSS) vulnerability in index.php in AutoIndex PHP Script 1.5.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
network
autoindex
4.3