Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0371 Unspecified vulnerability in Armagetron and Armagetron Advanced
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (freeze) via a large number of player connections that do not send any data.
network
low complexity
armagetron
5.0
2005-05-02 CVE-2005-0370 Denial-Of-Service vulnerability in Armagetron and Armagetron Advanced
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 and earlier allow remote attackers to cause a denial of service (network disconnection) via an empty UDP packet, which is not properly distinguished from the "no new packets" state of the associated socket.
network
low complexity
armagetron
5.0
2005-05-02 CVE-2005-0366 Inadequate Encryption Strength vulnerability in Gnupg
The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine whether an integrity check failed.
network
low complexity
gnupg CWE-326
5.0
2005-05-02 CVE-2005-0347 Remote Security vulnerability in RealArcade
Integer overflow in RealArcade 1.2.0.994 and earlier allows remote attackers to execute arbitrary code via an RGS file with an invalid size string for the GUID and game name, which leads to a buffer overflow.
network
high complexity
realnetworks
5.1
2005-05-02 CVE-2005-0345 Unspecified vulnerability in PHP Fusion PHP Fusion 4.0
viewthread.php in php-fusion 4.x does not check the (1) forum_id or (2) forum_cat parameters, which allows remote attackers to view protected forums via the thread_id parameter.
network
low complexity
php-fusion
5.0
2005-05-02 CVE-2005-0344 Directory Traversal vulnerability in Software602 602Lan Suite 2004.0.04.1221
Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a ..
network
low complexity
software602
5.0
2005-05-02 CVE-2005-0341 Cross-Site Scripting vulnerability in Apple Safari 1.2.4
Apple Safari 1.2.4 does not obey the Content-type field in the HTTP header and renders text as HTML, which allows remote attackers to inject arbitrary web script or HTML and perform cross-site scripting (XSS) attacks.
network
apple
4.3
2005-05-02 CVE-2005-0340 Remote Integer Overflow vulnerability in Apple Mac OS X AppleFileServer
Integer signedness error in Apple File Service (AFP Server) allows remote attackers to cause a denial of service (application crash) via a negative UAM string length in a FPLoginExt packet.
network
low complexity
apple
5.0
2005-05-02 CVE-2005-0336 Multiple vulnerability in Emotion Mediapartner web Server 5.0
Cross-site scripting (XSS) vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to inject arbitrary HTML or web script, as demonstrated using a URL containing ..
network
emotion
4.3
2005-05-02 CVE-2005-0335 Multiple vulnerability in Emotion Mediapartner web Server 5.0
Directory traversal vulnerability in EMotion MediaPartner Web Server 5.0 allows remote attackers to read arbitrary files via a ..
network
low complexity
emotion
5.0