Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0746 Remote Path Disclosure vulnerability in Novell Ichain 2.2/2.2.113/2.3
The Mini FTP server in Novell iChain 2.2 and 2.3 SP2 and earlier allows remote unauthenticated attackers to obtain the full path of the server via the PWD command.
network
low complexity
novell
5.0
2005-05-02 CVE-2005-0742 Cross-Site Scripting vulnerability in SUN Java System Application Server 7.0
Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
sun
4.3
2005-05-02 CVE-2005-0738 Resource Exhaustion vulnerability in Microsoft Exchange Server 2003
Stack consumption vulnerability in Microsoft Exchange Server 2003 SP1 allows users to cause a denial of service (hang) by deleting or moving a folder with deeply nested subfolders, which causes Microsoft Exchange Information Store service (Store.exe) to hang as a result of a large number of recursive calls.
network
low complexity
microsoft CWE-400
5.0
2005-05-02 CVE-2005-0734 Denial-Of-Service vulnerability in PY Software Active Webcam 5.5
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests.
network
low complexity
py-software
5.0
2005-05-02 CVE-2005-0733 Remote Security vulnerability in PY Software Active Webcam 5.5
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to determine the existence of files via an HTTP request with a full pathname, which produces different messages whether the file exists or not.
network
low complexity
py-software
5.0
2005-05-02 CVE-2005-0732 Remote Security vulnerability in PY Software Active Webcam 5.5
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to obtain the full path of the web server via a request for a non-existent filename, which leaks the full path in an error message.
network
low complexity
py-software
5.0
2005-05-02 CVE-2005-0730 Denial-Of-Service vulnerability in PY Software Active Webcam 5.5
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service via a request to a file on the floppy drive, as demonstrated using A:\a.txt.
network
low complexity
py-software
5.0
2005-05-02 CVE-2005-0724 Information Disclosure vulnerability in paFileDB
paFileDB 3.1 and earlier allows remote attackers to obtain sensitive information via (1) an invalid str parameter to pafiledb.php, or a direct request to (2) viewall.php, (3) stats.php, (4) search.php, (5) rate.php, (6) main.php, (7) license.php, (8) category.php, (9) download.php, (10) file.php, (11) email.php, or (12) admin.php, which reveals the path in a PHP error message.
network
low complexity
php-arena
5.0
2005-05-02 CVE-2005-0712 Unspecified vulnerability in Apple mac OS X 10.1/10.2/10.3.4
Mac OS X before 10.3.8 users world-writable permissions for certain directories, which may allow local users to gain privileges, possibly via the receipt cache or ColorSync profiles.
local
low complexity
apple
4.6
2005-05-02 CVE-2005-0710 Remote vulnerability in MySQL AB MySQL
MySQL 4.0.23 and earlier, and 4.1.x up to 4.1.10, allows remote authenticated users with INSERT and DELETE privileges to bypass library path restrictions and execute arbitrary libraries by using INSERT INTO to modify the mysql.func table, which is processed by the udf_init function.
local
low complexity
mysql oracle
4.6