Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-1125 Unspecified vulnerability in Avaya Libsafe
Race condition in libsafe 2.0.16 and earlier, when running in multi-threaded applications, allows attackers to bypass libsafe protection and exploit other vulnerabilities before the _libsafe_die function call is completed.
network
high complexity
avaya
5.1
2005-05-02 CVE-2005-1124 Local Security vulnerability in Solaris
Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.
local
low complexity
sun
4.6
2005-05-02 CVE-2005-1123 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Monkey-Project Monkey
Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service (memory corruption) via a request for a zero byte file.
network
low complexity
monkey-project CWE-119
5.0
2005-05-02 CVE-2005-1121 Remote Format String vulnerability in Oops! Proxy Server Auth
Format string vulnerability in the my_xlog function in lib.c for Oops! Proxy Server 1.5.23 and earlier, as called by the auth functions in the passwd_mysql and passwd_pgsql modules, may allow attackers to execute arbitrary code via a URL.
network
low complexity
igor-khasilev gentoo
5.0
2005-05-02 CVE-2005-1120 Remote HTML Injection vulnerability in IlohaMail Email Message
Multiple cross-site scripting (XSS) vulnerabilities in IlohaMail 0.8.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the e-mail (1) body, (2) filename, or (3) MIME type.
network
ilohamail
4.3
2005-05-02 CVE-2005-1116 Cross-Site Scripting vulnerability in phpBB
Cross-site scripting (XSS) vulnerability in the Calendar module for phpBB allow remote attackers to inject arbitrary web script or HTML via the start parameter to calendar_scheduler.php.
network
phpbb-group
4.3
2005-05-02 CVE-2005-1115 Cross-Site Scripting vulnerability in PHPBB Photo Album Module
Multiple cross-site scripting (XSS) vulnerabilities in Photo Album 2.0.53 module for phpBB allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) album_cat.php or (2) album_comment.php.
4.3
2005-05-02 CVE-2005-1113 Cross-Site Scripting vulnerability in PHPbb Group PHPbb Plus 1.3/1.51
Multiple cross-site scripting (XSS) vulnerabilities in PhpBB Plus 1.52 and earlier allow remote attackers to inject arbitrary web script or HTML via the bsid parameter to (1) groupcp.php, (2) index.php, (3) portal.php, (4) viewforum.php, or (5) viewtopic.php, (6) the c parameter to index.php, or (7) the article parameter to portal.php.
network
phpbb-group
4.3
2005-05-02 CVE-2005-1112 Unspecified vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 6.0 and earlier, when sharing the document root of the web server, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via an HTTP request with an invalid Host header, which causes the page to be processed by the web server instead of the JSP engine.
network
low complexity
ibm
5.0
2005-05-02 CVE-2005-1111 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.
local
high complexity
gnu debian canonical CWE-367
4.7