Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0127 Unspecified vulnerability in Apple mac OS X and mac OS X Server
Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
network
low complexity
apple
5.0
2005-05-02 CVE-2005-0121 Local Security vulnerability in Alexander Siegel Golddig 2.0
Multiple buffer overflows in golddig 2.0 and earlier allow local users to execute arbitrary code via (1) a long map name command line argument or (2) a long username as recorded in the USER environment variable.
local
low complexity
alexander-siegel
4.6
2005-05-02 CVE-2005-0083 Unspecified vulnerability in Mysql Maxdb 7.5.00
MySQL MaxDB 7.5.00 for Windows, and possibly earlier versions and other platforms, allows remote attackers to cause a denial of service (application crash) via invalid parameters to the (1) DBMCli_String::ReallocString, (2) DBMCli_String::operator, (3) DBMCli_Buffer::ForceResize, (4) DBMCli_Wizard::InstallDatabase, (5) DBMCli_Devspaces::Complete, (6) DBMWeb_TemplateWizard::askForWriteCountStep5, or (7) DBMWeb_DBMWeb::wizardDB functions, which triggers a null dereference.
network
low complexity
mysql
5.0
2005-05-02 CVE-2005-0080 Remote Security vulnerability in Ubuntu Linux
The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.
network
low complexity
gnu ubuntu
5.0
2005-05-02 CVE-2005-0079 Local Buffer Overflow vulnerability in Xtrlock 2.0
Buffer overflow in xtrlock 2.0 allows local users to cause a denial of service (application crash) and hijack the desktop session.
local
low complexity
xtrlock
4.6
2005-05-02 CVE-2005-0078 The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.
local
low complexity
debian kde redhat
4.6
2005-05-02 CVE-2005-0073 Unspecified vulnerability in Debian Sympa 3.3.3
Buffer overflow in queue.c in a support script for sympa 3.3.3, when running setuid, allows local users to execute arbitrary code.
local
low complexity
debian
4.6
2005-05-02 CVE-2005-0071 Remote File Access vulnerability in VDR Daemon
vdr before 1.2.6 does not securely create files, which allows attackers to overwrite arbitrary files.
network
low complexity
vdr
5.0
2005-05-02 CVE-2005-0056 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."
network
high complexity
microsoft
5.1
2005-05-02 CVE-2005-0054 Unspecified vulnerability in Microsoft IE and Internet Explorer
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."
network
high complexity
microsoft
5.1