Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-05-24 | CVE-2005-1718 | Denial-Of-Service vulnerability in LS Games WAR Times 1.03 Buffer overflow in LS Games War Times 1.03 and earlier allows remote attackers to cause a denial of service (server crash) via a long nickname. | 5.0 |
2005-05-24 | CVE-2005-1717 | Remote Denial of Service vulnerability in Zyxel Prestige 650R-31 3.40Ko.1 ZyXEL Prestige 650R-31 router running ZyNOS FW v3.40(KO.1) allows remote attackers to cause a denial of service (CPU consumption and network loss) via crafted fragmented IP packets. | 5.0 |
2005-05-24 | CVE-2005-1716 | Information Disclosure vulnerability in Topo 2.2/2.2.178 TOPo 2.2 (2.2.178) stores data files in the data directory under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as client IP addresses. | 5.0 |
2005-05-24 | CVE-2005-1715 | Index.PHP Cross-Site Scripting vulnerability in EJ3 Topo 2.2/2.2.178 Cross-site scripting (XSS) vulnerability in index.php for TOPo 2.2 (2.2.178) allows remote attackers to inject arbitrary web script or HTML via the (1) m, (2) s, (3) ID, or (4) t parameters, or the (5) field name, (6) Your Web field, or (7) email field in the comments section. network ej3 | 4.3 |
2005-05-24 | CVE-2005-1714 | Unspecified vulnerability in Netwin Surgemail 3.0C2 Cross-site scripting (XSS) vulnerability in NetWin SurgeMail 3.0c2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. network netwin | 4.3 |
2005-05-24 | CVE-2005-1713 | Unspecified vulnerability in S9Y Serendipity 0.8 Multiple cross-site scripting (XSS) vulnerabilities in Serendipity 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) templatedropdown and (2) shoutbox plugins. network s9y | 4.3 |
2005-05-24 | CVE-2005-1710 | Unspecified vulnerability in Bluecoat Reporter 7.1.1 Multiple cross-site scripting (XSS) vulnerabilities in Blue Coat Reporter before 7.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the username in an Add User window or (2) the license key (volatile.license_to_add parameter) in the Licensing page. network bluecoat | 4.3 |
2005-05-24 | CVE-2005-1708 | Remote Privilege Escalation vulnerability in Bluecoat Reporter 7.1.1 templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true. | 4.6 |
2005-05-24 | CVE-2005-1707 | Unspecified vulnerability in Gentoo Linux Webapp-Config 1.10 The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file. | 4.6 |
2005-05-24 | CVE-2005-1704 | Numeric Errors vulnerability in GNU GDB Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow. | 4.6 |