Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-07-11 CVE-2005-2201 Denial-Of-Service vulnerability in Xerox Workcentre 2128, Workcentre 2636 and Workcentre 3545
Unknown vulnerability in the MicroServer Web Server for Xerox WorkCentre Pro Color 2128, 2636, and 3545, version 0.001.04.044 through 0.001.04.504, allow attackers to cause a denial of service or access files via crafted HTTP requests.
network
low complexity
xerox
6.4
2005-07-11 CVE-2005-2192 Remote Security vulnerability in Alexander Palmo Simple PHP Blog 0.4.0
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote attackers to obtain passwords via a brute force attack.
network
low complexity
alexander-palmo
5.0
2005-07-11 CVE-2005-2191 Input Validation And Information Disclosure vulnerability in Comersus BackOffice
Multiple cross-site scripting (XSS) vulnerabilities in Comersus shopping cart allow remote attackers to inject arbitrary web script or HTML via the (1) name parameter to comersus_backoffice_listAssignedPricesToCustomer.asp or (2) message parameter to comersus_backoffice_message.asp.
4.3
2005-07-11 CVE-2005-2189 Information Disclosure vulnerability in Lantronix Securelinx 2.0/3.0
Lantronix SecureLinx console server running firmware 2.0 and 3.0 stores /etc/ssh under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as SSH private keys.
network
low complexity
lantronix
5.0
2005-07-11 CVE-2005-2187 Local Security vulnerability in IntruShield Security Management System
McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.
local
low complexity
mcafee
4.6
2005-07-11 CVE-2005-2179 Remote Security vulnerability in JAWS
PHP remote file inclusion vulnerability in BlogModel.php in Jaws 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via the path parameter.
network
low complexity
jaws
5.0
2005-07-11 CVE-2005-2177 Improper Input Validation vulnerability in Net-Snmp
Net-SNMP 5.0.x before 5.0.10.2, 5.2.x before 5.2.1.2, and 5.1.3, when net-snmp is using stream sockets such as TCP, allows remote attackers to cause a denial of service (daemon hang and CPU consumption) via a TCP packet of length 1, which triggers an infinite loop.
network
low complexity
net-snmp CWE-20
5.0
2005-07-11 CVE-2005-2170 Remote Denial Of Service vulnerability in IBM Tivoli Management Framework 4.1.1
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.
network
low complexity
ibm
5.0
2005-07-11 CVE-2005-2150 Unspecified vulnerability in Microsoft Windows 2000 and Windows NT
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.
network
low complexity
microsoft
5.0
2005-07-11 CVE-2005-1848 Unspecified vulnerability in Phystech Dhcpcd 1.3.17Pl2
The dhcpcd DHCP client before 1.3.22 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors that cause an out-of-bounds memory read.
network
low complexity
phystech
5.0