Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-01-16 CVE-2005-0294 Unspecified vulnerability in Minis 0.2.1
minis.php in Minis 0.2.1 allows remote attackers to cause a denial of service (infinite loop) via an HTTP request for a file that the web server does not have permission to read, as demonstrated using the month parameter.
network
low complexity
minis
5.0
2005-01-15 CVE-2005-0095 Denial Of Service vulnerability in Squid Proxy Web Cache Communication Protocol
The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.
network
low complexity
squid
5.0
2005-01-15 CVE-2005-0094 Remote Buffer Overflow vulnerability in Squid Proxy Gopher To HTML
Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.
network
low complexity
squid
5.0
2005-01-13 CVE-2005-0740 Remote Denial Of Service vulnerability in OpenBSD TCP Timestamp
The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout.
network
low complexity
openbsd
5.0
2005-01-13 CVE-2005-0381 Cross-Site Scripting vulnerability in Forumkit 1.0
Cross-site scripting (XSS) vulnerability in f.aspx in forumKIT 1.0 allows remote attackers to inject arbitrary web script or HTML via the members parameter.
network
forumkit
4.3
2005-01-13 CVE-2005-0069 Unspecified vulnerability in VIM Development Group VIM
The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.
local
low complexity
vim-development-group
4.6
2005-01-12 CVE-2005-0456 Unspecified vulnerability in Opera Browser
Opera 7.54 and earlier does not properly validate base64 encoded binary data in a data: (RFC 2397) URL, which causes the URL to be obscured in a download dialog, which may allow remote attackers to trick users into executing arbitrary code.
network
low complexity
opera
5.0
2005-01-11 CVE-2005-0117 Local Security vulnerability in XShisen
Buffer overflow in XShisen before 1.36 allows local users to execute arbitrary code via a long GECOS field.
local
low complexity
xshisen
4.6
2005-01-11 CVE-2005-0108 Integer Overflow vulnerability in Apache MOD Auth Radius 1.5.4
Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.
network
low complexity
apache
5.0
2005-01-11 CVE-2005-0097 Remote Denial of Service vulnerability in Squid Proxy Malformed NTLM Type 3 Message
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.
network
low complexity
squid
5.0