Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-02-12 CVE-2005-0430 Remote Denial of Service vulnerability in ID Software Quake 3 Engine Infostring Query
The Quake 3 engine, as used in multiple game packages, allows remote attackers to cause a denial of service (shutdown game server) and possibly crash the server via a long infostring, possibly triggering a buffer overflow.
network
low complexity
id-software
5.0
2005-02-10 CVE-2005-0364 Denial-Of-Service vulnerability in HP Hp-Ux 11.00/11.11/11.23
Unknown vulnerability in BIND 9.2.0 in HP-UX B.11.00, B.11.11, and B.11.23 allows remote attackers to cause a denial of service.
network
low complexity
hp
5.0
2005-02-09 CVE-2005-0367 File-Upload vulnerability in Argosoft Mail Server 1.8.7.3
Multiple directory traversal vulnerabilities in ArGoSoft Mail Server 1.8.7.3 allow remote authenticated users to read, delete, or upload arbitrary files via a ..
local
low complexity
argosoft
4.6
2005-02-09 CVE-2005-0362 Local Security vulnerability in AWStats
awstats.pl in AWStats 6.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) "pluginmode", (2) "loadplugin", or (3) "noloadplugin" parameters.
local
low complexity
awstats
4.6
2005-02-09 CVE-2004-0961 Attribute Decoding Denial Of Service vulnerability in FreeRADIUS
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
network
low complexity
freeradius redhat
5.0
2005-02-09 CVE-2004-0960 Attribute Decoding Denial Of Service vulnerability in FreeRADIUS
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
network
low complexity
freeradius redhat
5.0
2005-02-09 CVE-2004-0957 Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities. 6.8
2005-02-09 CVE-2004-0950 Information Disclosure vulnerability in Danware NetOp Remote Control
NetOp Host before 7.65 build 2004278 allows remote attackers to obtain sensitive hostname, username and local IP address information via (1) a NetOp HELO request, or (2) when responses are disabled, a "custom" HELO request.
network
low complexity
danware-data
5.0
2005-02-09 CVE-2004-0939 Denial-Of-Service vulnerability in Instant Virtual Extranet
changepassword.cgi in Neoteris Instant Virtual Extranet (IVE) 3.x and 4.x, with LDAP authentication or NT domain authentication enabled, does not limit the number of times a bad password can be entered, which allows remote attackers to guess passwords via a brute force attack.
network
low complexity
neoteris
5.0
2005-02-07 CVE-2005-0175 Unspecified vulnerability in Squid
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.
network
low complexity
squid
5.0